Help - Can I do an external pen-test in this network?

From: to.tushar@yahoo.com
Date: Fri Mar 07 2008 - 01:52:00 EST


('binary' encoding is not supported, stored as-is) Hi,
 
I have just completed my classes of Penetration Testing and have been asked to do a project.
I have an option to do either external or internal pen test.

I can do an internal pen-test in one organization I've got, however, I am not sure how I can do an external pen-test in this scenario. The following is the network. Please tell me if I can do an external pentest in this case and where can I start.
 
Internet -> router / modem provided by ISP (only static IP in organization)-> Switch -> about 100 systems in internal network (pvt IPs).
Webserver & mails are hosted on public server.
 
Ping: success
Tried nmap: Host seems down. If it is really up, but blocking our ping probes, try -P0 (we are scanning a router here, so it won't work)

Is there anyway I can get into this organization by doing an external pen-test. This is a small company into s/w development and uses only messengers to communicate with the outside world / clients etc. No major servers inside organization and none with pub IP address.
 
If you need any more info, please lemme know.
 
Regards,
Tushar

------------------------------------------------------------------------
This list is sponsored by: Cenzic

Need to secure your web apps NOW?
Cenzic finds more, "real" vulnerabilities fast.
Click to try it, buy it or download a solution FREE today!

http://www.cenzic.com/downloads
------------------------------------------------------------------------



This archive was generated by hypermail 2.1.7 : Sat Apr 12 2008 - 10:58:27 EDT