|
|||||||||||
|
RE: how to isolate a virtual hosted website, in order to do a A&P?
From: Pete Herzog <lists(at)isecom.org>
Date: Tue Feb 11 2003 - 03:48:22 EST
It is also up to the client to tell the ISP what he is asking for and it is your job to remind the client of this. You are not to notify the ISP nor get involved in their contract dispute over whether or not they may authorize a security test. You may not test anything that isn't similar to normal web traffic or which may disrupt the other customers hosted on that server or with that ISP. You are restricted to mostly the Information Security Testing modules of the OSSTMM (www.osstmm.org). Sincerely,
-pete.
-----Original Message-----
a customer has asked me to take a look at his web page and "poke around", initial investigation shows that it is hosted on a large web hosting companies IP# and is a virtual host off of that IP#. Obviously hammering that main webhosting companies box would be a no no, so how can i focus my security review on that clients specific box? they are using apache, not IIS. Any thoughts? This list is provided by the SecurityFocus Security Intelligence Alert (SIA) Service. For more information on SecurityFocus' SIA service which automatically alerts you to the latest security vulnerabilities please see: https://alerts.securityfocus.com/ This list is provided by the SecurityFocus Security Intelligence Alert (SIA) Service. For more information on SecurityFocus' SIA service which automatically alerts you to the latest security vulnerabilities please see: https://alerts.securityfocus.com/ Received on Tue Feb 11 09:41:26 2003 This archive was generated by hypermail 2.1.8 : Wed Aug 23 2006 - 14:02:32 EDT |
||||||||||
|
|||||||||||