<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
		>
<channel>
	<title>Comments on: Hands On: Ep 9 &#8211; Penetration Testing</title>
	<atom:link href="http://webstudio.ciopakistan.com/2009/04/09/hands-on-ep-9-penetration-testing/feed/" rel="self" type="application/rss+xml" />
	<link>http://webstudio.ciopakistan.com/2009/04/09/hands-on-ep-9-penetration-testing/</link>
	<description>Pakistan&#039;s first Online, On-Demand Technology Media Channel</description>
	<lastBuildDate>Tue, 07 Sep 2010 01:12:28 +0000</lastBuildDate>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.0</generator>
	<item>
		<title>By: talha</title>
		<link>http://webstudio.ciopakistan.com/2009/04/09/hands-on-ep-9-penetration-testing/comment-page-1/#comment-517</link>
		<dc:creator>talha</dc:creator>
		<pubDate>Tue, 14 Apr 2009 23:42:41 +0000</pubDate>
		<guid isPermaLink="false">http://webstudio.ciopakistan.com/?p=1136#comment-517</guid>
		<description>@Qazi,

Thanks for mentioning and I agree with you. Although there is a difference, but I just wanted to keep it simpler for audience.

There are many suites of automated tools and online services available that deal with both at same time. And as a PCI Auditor, I also deal with both at same time and the official term we use for both is &quot;Network Scanning&quot;.</description>
		<content:encoded><![CDATA[<p>@Qazi,</p>
<p>Thanks for mentioning and I agree with you. Although there is a difference, but I just wanted to keep it simpler for audience.</p>
<p>There are many suites of automated tools and online services available that deal with both at same time. And as a PCI Auditor, I also deal with both at same time and the official term we use for both is &#8220;Network Scanning&#8221;.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Qazi Ahmed</title>
		<link>http://webstudio.ciopakistan.com/2009/04/09/hands-on-ep-9-penetration-testing/comment-page-1/#comment-512</link>
		<dc:creator>Qazi Ahmed</dc:creator>
		<pubDate>Mon, 13 Apr 2009 21:21:31 +0000</pubDate>
		<guid isPermaLink="false">http://webstudio.ciopakistan.com/?p=1136#comment-512</guid>
		<description>What you have posted here is Vulnerability Assessment and not Penetration Testing and yes, there is a huge difference in both.

Nessus is a vulnerability scanning tool which only identifies &quot;possible&quot; security vulnerabilities (with a hell lot of false +/-).

Vulnerability Assessment checks for the visible/obvious security issues but Penetration Testing goes further and not only identifies security vulnerabilities but also exploits them to demonstrate an actual hacker attack and includes steps such as footprinting, scanning, enumeration, sniffing, packet inspection, password cracking, bufferover flow attacks, exploitation, backdoor, denial of service, erase logs, patch and report to name a few activities.</description>
		<content:encoded><![CDATA[<p>What you have posted here is Vulnerability Assessment and not Penetration Testing and yes, there is a huge difference in both.</p>
<p>Nessus is a vulnerability scanning tool which only identifies &#8220;possible&#8221; security vulnerabilities (with a hell lot of false +/-).</p>
<p>Vulnerability Assessment checks for the visible/obvious security issues but Penetration Testing goes further and not only identifies security vulnerabilities but also exploits them to demonstrate an actual hacker attack and includes steps such as footprinting, scanning, enumeration, sniffing, packet inspection, password cracking, bufferover flow attacks, exploitation, backdoor, denial of service, erase logs, patch and report to name a few activities.</p>
]]></content:encoded>
	</item>
</channel>
</rss>
