Re: Re: the best pen-testing live linux distro????

From: arif.jatmoko@sea.ccamatil.com
Date: Wed Jul 19 2006 - 07:25:12 EDT


I think there are no 'the best' live distro, all got their own advantages.
What is the main concerns with 'the  best' here ? If you see Whax, Auditor,
or BackTrac, they are provide same tools inside. How you can use them is
depend on your skillz ...

Arif Jatmoko
|+---------------------+--------------------------------------------------|
|| josh.perrymon@pack| |
|| etfocus.com |         To:        pen-test@securityfocus.com |
|| |         cc: |
|| 07/19/2006 01:20 |         Subject:        Re: Re: the best |
|| PM | pen-testing live linux distro???? |
|| | |
|+---------------------+--------------------------------------------------|

Hello Ahmad,

You can find more information about the new OWASP distro here:

http://www.owasp.org/index.php/Category:OWASP_Testing_Project

The current version is in Alpha stage and will be released to BETA after
this round of testing.

The distro is named "LabRat" and the main focus will be application
pen-testing.

It's based of Morhpix/ Debian.

This distro was created after using current distro's as a base install for
pen=testing attack machines. Current distro's like BackTrack didn't have
the tools we needed for app testing ( WebScarab, Paros, Fuzzing tools , etc
)

((((Nothing negative against Backtrack- the guys have done heaps of work
and it's the best distro out currently.))))

So the LabRat distro will have OWASP tools and testing guide as a
reference. It will also include webgoat for training purposes.

We are spending a lot of time organizing the menu structure and layout of
the GUI environment.

PacketFocus will also include tools for RFID, VOIP, and infrastructure
hacking.

Wireless tools will be included but not a focus- Backtrack does this area
really well.

Cheers,

Josh Perrymon
Packetfocus.com

------------------------------------------------------------------------------
This List Sponsored by: Cenzic

Concerned about Web Application Security?
Why not go with the #1 solution - Cenzic, the only one to win the Analyst's
Choice Award from eWeek. As attacks through web applications continue to
rise,
you need to proactively protect your applications from hackers. Cenzic has
the
most comprehensive solutions to meet your application security penetration
testing and vulnerability management needs. You have an option to go with a
managed service (Cenzic ClickToSecure) or an enterprise software
(Cenzic Hailstorm). Download FREE whitepaper on how a managed service can
help you: http://www.cenzic.com/news_events/wpappsec.php
And, now for a limited time we can do a FREE audit for you to confirm your
results from other product. Contact us at request@cenzic.com for details.
------------------------------------------------------------------------------

_______________________________________________________________________________
Visit us at www.coca-colabottling.co.id

CAUTION:
This message may contain privileged and confidential information intended only for the use of the addressee named above. If you are not the intended recipient of this message, you are hereby notified that any use, dissemination,distribution, or reproduction of this message is prohibited. If you have received this message in error, please notify Coca-Cola Bottling Indonesia immediately. Any views expressed in this message are those of the individual sender and may not necessarily reflect the views of Coca-Cola Bottling Indonesia.

------------------------------------------------------------------------------
This List Sponsored by: Cenzic

Concerned about Web Application Security?
Why not go with the #1 solution - Cenzic, the only one to win the Analyst's
Choice Award from eWeek. As attacks through web applications continue to rise,
you need to proactively protect your applications from hackers. Cenzic has the
most comprehensive solutions to meet your application security penetration
testing and vulnerability management needs. You have an option to go with a
managed service (Cenzic ClickToSecure) or an enterprise software
(Cenzic Hailstorm). Download FREE whitepaper on how a managed service can
help you: http://www.cenzic.com/news_events/wpappsec.php
And, now for a limited time we can do a FREE audit for you to confirm your
results from other product. Contact us at request@cenzic.com for details.
------------------------------------------------------------------------------



This archive was generated by hypermail 2.1.7 : Sat Apr 12 2008 - 10:56:21 EDT