<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
		>
<channel>
	<title>Comments on: 3 Reasons why Automated Vulnerability Scanning does not work</title>
	<atom:link href="http://www.ivizsecurity.com/blog/penetration-testing/what-everybody-ought-to-know-about-free-vulnerability-scanning/feed/" rel="self" type="application/rss+xml" />
	<link>http://www.ivizsecurity.com/blog/penetration-testing/what-everybody-ought-to-know-about-free-vulnerability-scanning/</link>
	<description>The Authoritative Blog on Penetration Testing</description>
	<lastBuildDate>Thu, 13 Oct 2011 11:49:03 +0000</lastBuildDate>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.3.1</generator>
	<item>
		<title>By: Vasant</title>
		<link>http://www.ivizsecurity.com/blog/penetration-testing/what-everybody-ought-to-know-about-free-vulnerability-scanning/comment-page-1/#comment-3248</link>
		<dc:creator>Vasant</dc:creator>
		<pubDate>Fri, 05 Mar 2010 06:57:35 +0000</pubDate>
		<guid isPermaLink="false">http://www.ivizsecurity.com/blog/?p=99#comment-3248</guid>
		<description>Lets see if Pen-tests could live up what the 3 reasons.

R#1  Pentests also will only CONFIRM the existence of the vulnerability and that its exploitable, BUT still doesn&#039;t protect the network.   

R#2  So how will the patch availablity or its unavailibility be solved by Pen-testing.    If you have a vulnerability which has been proved to be exploitable by a pen-test AND still you don&#039;t have a patch -- you still at square 1.  

R#3  Yes agree false positives is a problem with VA tools and pen-testing can help confirm a vulnerability but thats not a reason why VA tools work.  Without VA you couldn&#039;t even think of pen-testing.  Could you have done the pen-test without the knowledge of the vulnerability. 

Point is VA is not the end all.  Pen-testing can help in confirming the vulnerability or not but saying VA don&#039;t work is not correct.  Its like you want to show humans bones can withstand more than twice the human body weight.   I don&#039;t need to lift a 150 kg to show it everytime.  If its proved, people do get the message.  

Love to hear your comments.</description>
		<content:encoded><![CDATA[<p>Lets see if Pen-tests could live up what the 3 reasons.</p>
<p>R#1  Pentests also will only CONFIRM the existence of the vulnerability and that its exploitable, BUT still doesn&#8217;t protect the network.   </p>
<p>R#2  So how will the patch availablity or its unavailibility be solved by Pen-testing.    If you have a vulnerability which has been proved to be exploitable by a pen-test AND still you don&#8217;t have a patch &#8212; you still at square 1.  </p>
<p>R#3  Yes agree false positives is a problem with VA tools and pen-testing can help confirm a vulnerability but thats not a reason why VA tools work.  Without VA you couldn&#8217;t even think of pen-testing.  Could you have done the pen-test without the knowledge of the vulnerability. </p>
<p>Point is VA is not the end all.  Pen-testing can help in confirming the vulnerability or not but saying VA don&#8217;t work is not correct.  Its like you want to show humans bones can withstand more than twice the human body weight.   I don&#8217;t need to lift a 150 kg to show it everytime.  If its proved, people do get the message.  </p>
<p>Love to hear your comments.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Vasant</title>
		<link>http://www.ivizsecurity.com/blog/penetration-testing/what-everybody-ought-to-know-about-free-vulnerability-scanning/comment-page-1/#comment-3247</link>
		<dc:creator>Vasant</dc:creator>
		<pubDate>Fri, 05 Mar 2010 06:47:26 +0000</pubDate>
		<guid isPermaLink="false">http://www.ivizsecurity.com/blog/?p=99#comment-3247</guid>
		<description>So you mean to say we should all stop doing VA .. and just do Pen tests ..   Wonder how pen-tests know about vulnerabilities, if they don&#039;t scan for vulnerabilities.

Hmmm. ...</description>
		<content:encoded><![CDATA[<p>So you mean to say we should all stop doing VA .. and just do Pen tests ..   Wonder how pen-tests know about vulnerabilities, if they don&#8217;t scan for vulnerabilities.</p>
<p>Hmmm. &#8230;</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: penetration testers - StartTags.com</title>
		<link>http://www.ivizsecurity.com/blog/penetration-testing/what-everybody-ought-to-know-about-free-vulnerability-scanning/comment-page-1/#comment-3056</link>
		<dc:creator>penetration testers - StartTags.com</dc:creator>
		<pubDate>Thu, 28 Jan 2010 08:48:19 +0000</pubDate>
		<guid isPermaLink="false">http://www.ivizsecurity.com/blog/?p=99#comment-3056</guid>
		<description>[...] Security and Pen Testers need to know to get the job done &#124; Ajit Gaddam: TechNews and Security ...3 Reasons why Automated Vulnerability Scanning does not workResults from Automated Vulnerability scanning is often misleading while managing the security of a [...]</description>
		<content:encoded><![CDATA[<p>[...] Security and Pen Testers need to know to get the job done | Ajit Gaddam: TechNews and Security &#8230;3 Reasons why Automated Vulnerability Scanning does not workResults from Automated Vulnerability scanning is often misleading while managing the security of a [...]</p>
]]></content:encoded>
	</item>
</channel>
</rss>

