RE: Vulnerability Assessment of a EAL 4 system

From: Marc Doudiet (marc.doudiet@psdsecurite.com)
Date: Wed Nov 01 2006 - 16:19:21 EST


Hi,

I don't think that iptables is a criteria for EAL. I suggest you check
http://www.commoncriteriaportal.org/public/files/ccusersguide.pdf

Nist provide infos for common criteria.

Hope this helps.

Marc Doudiet

-----Message d'origine-----
De : listbounce@securityfocus.com [mailto:listbounce@securityfocus.com] De
la part de castellan2004-fd@yahoo.com
Envoyé : mercredi, 1. novembre 2006 11:12
À : pen-test@securityfocus.com
Objet : Vulnerability Assessment of a EAL 4 system

I am looking at a Linux server which has been accredited as a EAL4 system by
IBM. During the assessment, I was looking for standard Linux protections
like iptables, ssh etc. On this server, there is no iptables.

Regardless, I would like to know how to evaluate a EAL
4 system. What do you need to look for in the EAL 4 system in production
that could become vulnerable?

Thank you in advance for any help.

------------------------------------------------------------------------
This List Sponsored by: Cenzic

Need to secure your web apps?
Cenzic Hailstorm finds vulnerabilities fast.
Click the link to buy it, try it or download Hailstorm for FREE.
http://www.cenzic.com/products_services/download_hailstorm.php?camp=70160000
0008bOW
------------------------------------------------------------------------





This archive was generated by hypermail 2.1.7 : Sat Apr 12 2008 - 10:57:16 EDT