<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
		>
<channel>
	<title>Comments on: Automated Penetration Testing with CORE IMPACT</title>
	<atom:link href="http://www.spylogic.net/2008/02/automated-penetration-testing-with-core-impact/feed/" rel="self" type="application/rss+xml" />
	<link>http://www.spylogic.net/2008/02/automated-penetration-testing-with-core-impact/</link>
	<description></description>
	<lastBuildDate>Sun, 18 Sep 2011 21:48:21 +0000</lastBuildDate>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
		<item>
		<title>By: agent0x0</title>
		<link>http://www.spylogic.net/2008/02/automated-penetration-testing-with-core-impact/comment-page-1/#comment-13</link>
		<dc:creator>agent0x0</dc:creator>
		<pubDate>Mon, 25 Feb 2008 23:26:24 +0000</pubDate>
		<guid isPermaLink="false">#comment-13</guid>
		<description>Good call on SAINT.  I always thought that SAINT was just a vulnerability scanner like Nessus but I do see that they have a penetration testing tool called &quot;SAINTexploit&quot; integrated in the product.  I would be interested in hearing how this product differs from CORE or Canvas.&lt;br /&gt;
&lt;br /&gt;
You are right, CORE doesn&#039;t do well with patched and hardened hosts.  However, I have found that the client side exploits are really the best part of the product.  Just having the ability to email &quot;fake&quot; phishing emails or SPAM to users and exploit the local system pays for itself.   Sure, you can do this on your own without CORE but having everything integrated into a single product speeds things up.  I have successfully used CORE to test the &quot;human element&quot; and it does this very well.</description>
		<content:encoded><![CDATA[<p>Good call on SAINT.  I always thought that SAINT was just a vulnerability scanner like Nessus but I do see that they have a penetration testing tool called &quot;SAINTexploit&quot; integrated in the product.  I would be interested in hearing how this product differs from CORE or Canvas.</p>
<p>You are right, CORE doesn&#8217;t do well with patched and hardened hosts.  However, I have found that the client side exploits are really the best part of the product.  Just having the ability to email &quot;fake&quot; phishing emails or SPAM to users and exploit the local system pays for itself.   Sure, you can do this on your own without CORE but having everything integrated into a single product speeds things up.  I have successfully used CORE to test the &quot;human element&quot; and it does this very well.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: CG</title>
		<link>http://www.spylogic.net/2008/02/automated-penetration-testing-with-core-impact/comment-page-1/#comment-12</link>
		<dc:creator>CG</dc:creator>
		<pubDate>Mon, 25 Feb 2008 22:56:52 +0000</pubDate>
		<guid isPermaLink="false">#comment-12</guid>
		<description>you forgot about SAINT.&lt;br /&gt;
&lt;br /&gt;
I personally have had little luck on &quot;real&quot; networks using Core, Canvas or SAINT.  By real i mean networks that aren&#039;t vuln to DCOM and are actually patching and hardening.  not saying anything bad about any of the products, just something to keep in mind when its time to put those tools to test in a real environment.  If you have had success i&#039;d be interested to hear/read about it.&lt;br /&gt;
&lt;br /&gt;
-CG</description>
		<content:encoded><![CDATA[<p>you forgot about SAINT.</p>
<p>I personally have had little luck on &quot;real&quot; networks using Core, Canvas or SAINT.  By real i mean networks that aren&#8217;t vuln to DCOM and are actually patching and hardening.  not saying anything bad about any of the products, just something to keep in mind when its time to put those tools to test in a real environment.  If you have had success i&#8217;d be interested to hear/read about it.</p>
<p>-CG</p>
]]></content:encoded>
	</item>
</channel>
</rss>

