19.04.2013 Views

2KKUU7ita

2KKUU7ita

2KKUU7ita

SHOW MORE
SHOW LESS

You also want an ePaper? Increase the reach of your titles

YUMPU automatically turns print PDFs into web optimized ePapers that Google loves.

Chapter 21<br />

Ten Deadly Mistakes<br />

S everal deadly mistakes can wreak havoc on your ethical hacking<br />

outcomes and even your career. In this chapter, I discuss the potential<br />

pitfalls to be keenly aware of.<br />

Not Getting Prior Approval<br />

Getting documented approval in advance, such as an e-mail, an internal<br />

memo, or a formal contract for your ethical hacking efforts — whether it’s<br />

from management or from your client — is an absolute must. It’s your Get<br />

Out of Jail Free card.<br />

Allow no exceptions here — especially when you’re doing work for clients:<br />

Make sure you get a signed copy of this document for your files and for your<br />

lawyer.<br />

Assuming That You Can Find All<br />

Vulnerabilities during Your Tests<br />

So many security vulnerabilities exist — known and unknown — that you<br />

won’t find them all during your testing. Don’t make any guarantees that you’ll<br />

find all the security vulnerabilities in a system. You’ll be starting something<br />

that you can’t finish.<br />

If you did well studying probability and statistics in high school or college,<br />

you may consider putting together some confidence intervals to show what<br />

you truly expect to find.

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!