<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
		>
<channel>
	<title>Comments on: Vulnerability vs. Pen test</title>
	<atom:link href="http://sechero.com/vulnerability-vs-pen-test/feed/" rel="self" type="application/rss+xml" />
	<link>http://sechero.com/vulnerability-vs-pen-test/</link>
	<description>If it's about security, you heard it here first</description>
	<lastBuildDate>Sat, 30 May 2009 10:40:51 +0000</lastBuildDate>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	
	<item>
		<title>By: "Penetration Testing (pen-test) Mailing List" </title>
		<link>http://sechero.com/vulnerability-vs-pen-test/comment-page-1/#comment-252</link>
		<dc:creator>"Penetration Testing (pen-test) Mailing List" </dc:creator>
		<pubDate>Mon, 27 Apr 2009 04:14:30 +0000</pubDate>
		<guid isPermaLink="false">http://sechero.com/vulnerability-vs-pen-test/#comment-252</guid>
		<description>&lt;p&gt;&lt;/p&gt;
&lt;p&gt;&lt;h1&gt;&lt;a href=&quot;http://seclists.org/pen-test/2009/Apr/0171.html&quot;&gt;Re: Vulnerability vs. Pen test&lt;/a&gt;&lt;/h1&gt;&lt;/p&gt;
&lt;p&gt;Posted by bartlettNSF on Apr 27&lt;p&gt;&lt;/p&gt;
&lt;p&gt; &lt;p&gt; James Lay wrote: &lt;br /&gt; &gt;&gt; So part of PCI DSS requirements are for a quarterly vulnerability &lt;br /&gt; &gt;&gt; assessment, and a yearly pentest.  My question is:  is Nessus considered &lt;br /&gt; &gt;&gt; just a vulnerability scanning app?  Thanks. &lt;br /&gt; &gt;&gt; &lt;br /&gt; &gt;&gt; James &lt;br /&gt; &gt;&gt;      &lt;br /&gt; &gt; &lt;br /&gt; &gt; &lt;br /&gt; &gt; Thanks...&lt;p&gt;URL: &lt;a href=&quot;http://seclists.org/pen-test/2009/Apr/0171.html&quot;&gt;http://seclists.org/pen-test/2009/Apr/0171.html&lt;/a&gt;&lt;/p&gt;&lt;/p&gt;
&lt;p&gt;&lt;/p&gt;
&lt;p&gt;&lt;/p&gt;

</description>
		<content:encoded><![CDATA[</p>
<p>
<h1><a href="http://seclists.org/pen-test/2009/Apr/0171.html">Re: Vulnerability vs. Pen test</a></h1>
</p>
<p>Posted by bartlettNSF on Apr 27</p>
</p>
<p> James Lay wrote: <br /> &gt;&gt; So part of PCI DSS requirements are for a quarterly vulnerability <br /> &gt;&gt; assessment, and a yearly pentest.  My question is:  is Nessus considered <br /> &gt;&gt; just a vulnerability scanning app?  Thanks. <br /> &gt;&gt; <br /> &gt;&gt; James <br /> &gt;&gt;      <br /> &gt; <br /> &gt; <br /> &gt; Thanks&#8230;</p>
<p>URL: <a href="http://seclists.org/pen-test/2009/Apr/0171.html">http://seclists.org/pen-test/2009/Apr/0171.html</a></p></p>
]]></content:encoded>
	</item>
	<item>
		<title>By: "Penetration Testing (pen-test) Mailing List" </title>
		<link>http://sechero.com/vulnerability-vs-pen-test/comment-page-1/#comment-249</link>
		<dc:creator>"Penetration Testing (pen-test) Mailing List" </dc:creator>
		<pubDate>Sun, 26 Apr 2009 14:58:54 +0000</pubDate>
		<guid isPermaLink="false">http://sechero.com/vulnerability-vs-pen-test/#comment-249</guid>
		<description>&lt;p&gt;&lt;/p&gt;
&lt;p&gt;&lt;h1&gt;&lt;a href=&quot;http://seclists.org/pen-test/2009/Apr/0163.html&quot;&gt;Re: Vulnerability vs. Pen test&lt;/a&gt;&lt;/h1&gt;&lt;/p&gt;
&lt;p&gt;Posted by James Lay on Apr 26&lt;p&gt;&lt;/p&gt;
&lt;p&gt; &lt;p&gt; &gt; So part of PCI DSS requirements are for a quarterly vulnerability &lt;br /&gt; &gt; assessment, and a yearly pentest.  My question is:  is Nessus considered &lt;br /&gt; &gt; just a vulnerability scanning app?  Thanks. &lt;br /&gt; &gt;  &lt;br /&gt; &gt; James &lt;br /&gt; &lt;p&gt;&lt;p&gt;Thanks for all the feedback on this.  Guess my next question then is what &lt;br /&gt;...&lt;p&gt;URL: &lt;a href=&quot;http://seclists.org/pen-test/2009/Apr/0163.html&quot;&gt;http://seclists.org/pen-test/2009/Apr/0163.html&lt;/a&gt;&lt;/p&gt;&lt;/p&gt;
&lt;p&gt;&lt;/p&gt;
&lt;p&gt;&lt;/p&gt;

</description>
		<content:encoded><![CDATA[</p>
<p>
<h1><a href="http://seclists.org/pen-test/2009/Apr/0163.html">Re: Vulnerability vs. Pen test</a></h1>
</p>
<p>Posted by James Lay on Apr 26</p>
</p>
<p> &gt; So part of PCI DSS requirements are for a quarterly vulnerability <br /> &gt; assessment, and a yearly pentest.  My question is:  is Nessus considered <br /> &gt; just a vulnerability scanning app?  Thanks. <br /> &gt;  <br /> &gt; James  </p>
</p>
<p>Thanks for all the feedback on this.  Guess my next question then is what <br />&#8230;</p>
<p>URL: <a href="http://seclists.org/pen-test/2009/Apr/0163.html">http://seclists.org/pen-test/2009/Apr/0163.html</a></p></p>
]]></content:encoded>
	</item>
	<item>
		<title>By: "Penetration Testing (pen-test) Mailing List" </title>
		<link>http://sechero.com/vulnerability-vs-pen-test/comment-page-1/#comment-246</link>
		<dc:creator>"Penetration Testing (pen-test) Mailing List" </dc:creator>
		<pubDate>Fri, 24 Apr 2009 20:13:01 +0000</pubDate>
		<guid isPermaLink="false">http://sechero.com/vulnerability-vs-pen-test/#comment-246</guid>
		<description>&lt;p&gt;&lt;/p&gt;
&lt;p&gt;&lt;h1&gt;&lt;a href=&quot;http://seclists.org/pen-test/2009/Apr/0161.html&quot;&gt;Re: Vulnerability vs. Pen test&lt;/a&gt;&lt;/h1&gt;&lt;/p&gt;
&lt;p&gt;Posted by R. DuFresne on Apr 24&lt;p&gt;&lt;/p&gt;
&lt;p&gt; &lt;p&gt; &lt;p&gt;&lt;p&gt;&lt;p&gt;Yes. &lt;br /&gt; &lt;p&gt;Thanks, &lt;br /&gt; &lt;p&gt;Ron DuFresne &lt;br /&gt; &lt;p&gt;On Wed, 22 Apr 2009, jlay_at_slave-tothe-box&#046;net wrote: &lt;br /&gt; &lt;p&gt;&gt; So part of PCI DSS requirements are for a quarterly vulnerability &lt;br /&gt; &gt; assessment, and a yearly pentest.  My question is:  is Nessus considered &lt;br /&gt; &gt; just a vulnerability scanning app?  Thanks. &lt;br /&gt; &gt; &lt;br /&gt; ...&lt;p&gt;URL: &lt;a href=&quot;http://seclists.org/pen-test/2009/Apr/0161.html&quot;&gt;http://seclists.org/pen-test/2009/Apr/0161.html&lt;/a&gt;&lt;/p&gt;&lt;/p&gt;
&lt;p&gt;&lt;/p&gt;
&lt;p&gt;&lt;/p&gt;

</description>
		<content:encoded><![CDATA[</p>
<p>
<h1><a href="http://seclists.org/pen-test/2009/Apr/0161.html">Re: Vulnerability vs. Pen test</a></h1>
</p>
<p>Posted by R. DuFresne on Apr 24</p>
</p>
</p>
</p>
<p>Yes.  </p>
<p>Thanks,  </p>
<p>Ron DuFresne  </p>
<p>On Wed, 22 Apr 2009, jlay_at_slave-tothe-box&#46;net wrote:  </p>
<p>&gt; So part of PCI DSS requirements are for a quarterly vulnerability <br /> &gt; assessment, and a yearly pentest.  My question is:  is Nessus considered <br /> &gt; just a vulnerability scanning app?  Thanks. <br /> &gt; <br /> &#8230;</p>
<p>URL: <a href="http://seclists.org/pen-test/2009/Apr/0161.html">http://seclists.org/pen-test/2009/Apr/0161.html</a></p></p>
]]></content:encoded>
	</item>
	<item>
		<title>By: "Penetration Testing (pen-test) Mailing List" </title>
		<link>http://sechero.com/vulnerability-vs-pen-test/comment-page-1/#comment-236</link>
		<dc:creator>"Penetration Testing (pen-test) Mailing List" </dc:creator>
		<pubDate>Fri, 24 Apr 2009 08:31:41 +0000</pubDate>
		<guid isPermaLink="false">http://sechero.com/vulnerability-vs-pen-test/#comment-236</guid>
		<description>&lt;p&gt;&lt;/p&gt;
&lt;p&gt;&lt;h1&gt;&lt;a href=&quot;http://seclists.org/pen-test/2009/Apr/0148.html&quot;&gt;Re: Vulnerability vs. Pen test&lt;/a&gt;&lt;/h1&gt;&lt;/p&gt;
&lt;p&gt;Posted by Jeffrey Walton on Apr 24&lt;p&gt;&lt;/p&gt;
&lt;p&gt; &lt;p&gt; Hi James, &lt;br /&gt; &lt;p&gt;You might be interested in &#039;Nessus Network Auditing&#039; by Carey, &lt;br /&gt; Criscuolo, and Petruzzi (ISBN 978-1-59749-208-9) in addition to &lt;br /&gt; Ulises&#039; references. &lt;br /&gt; &lt;p&gt;Jeff &lt;br /&gt; &lt;p&gt;On 4/22/09, jlay_at_slave-tothe-box&#046;net &lt;jlay_at_slave-tothe-box&#046;net&gt; wrote: &lt;br /&gt; &gt; So part of PCI DSS requirements...&lt;p&gt;URL: &lt;a href=&quot;http://seclists.org/pen-test/2009/Apr/0148.html&quot;&gt;http://seclists.org/pen-test/2009/Apr/0148.html&lt;/a&gt;&lt;/p&gt;&lt;/p&gt;
&lt;p&gt;&lt;/p&gt;
&lt;p&gt;&lt;/p&gt;

</description>
		<content:encoded><![CDATA[</p>
<p>
<h1><a href="http://seclists.org/pen-test/2009/Apr/0148.html">Re: Vulnerability vs. Pen test</a></h1>
</p>
<p>Posted by Jeffrey Walton on Apr 24</p>
</p>
<p> Hi James,  </p>
<p>You might be interested in &#8216;Nessus Network Auditing&#8217; by Carey, <br /> Criscuolo, and Petruzzi (ISBN 978-1-59749-208-9) in addition to <br /> Ulises&#8217; references.  </p>
<p>Jeff  </p>
<p>On 4/22/09, jlay_at_slave-tothe-box&#46;net &lt;jlay_at_slave-tothe-box&#46;net&gt; wrote: <br /> &gt; So part of PCI DSS requirements&#8230;</p>
<p>URL: <a href="http://seclists.org/pen-test/2009/Apr/0148.html">http://seclists.org/pen-test/2009/Apr/0148.html</a></p></p>
]]></content:encoded>
	</item>
	<item>
		<title>By: "Penetration Testing (pen-test) Mailing List" </title>
		<link>http://sechero.com/vulnerability-vs-pen-test/comment-page-1/#comment-230</link>
		<dc:creator>"Penetration Testing (pen-test) Mailing List" </dc:creator>
		<pubDate>Fri, 24 Apr 2009 03:10:54 +0000</pubDate>
		<guid isPermaLink="false">http://sechero.com/vulnerability-vs-pen-test/#comment-230</guid>
		<description>&lt;p&gt;&lt;/p&gt;
&lt;p&gt;&lt;h1&gt;&lt;a href=&quot;http://seclists.org/pen-test/2009/Apr/0143.html&quot;&gt;Re: Vulnerability vs. Pen test&lt;/a&gt;&lt;/h1&gt;&lt;/p&gt;
&lt;p&gt;Posted by Ulises2k on Apr 24&lt;p&gt;&lt;/p&gt;
&lt;p&gt; &lt;p&gt; Yes, &lt;br /&gt; Check this: &lt;br /&gt; http://blog.tenablesecurity.com/2007/07/pci-configurati.html &lt;br /&gt; http://pcianswers.com/2007/07/11/nessus-audit-files-and-uk-petitions-to-make-pci-law/ &lt;br /&gt; &lt;p&gt;&lt;p&gt;URL: &lt;a href=&quot;http://seclists.org/pen-test/2009/Apr/0143.html&quot;&gt;http://seclists.org/pen-test/2009/Apr/0143.html&lt;/a&gt;&lt;/p&gt;&lt;/p&gt;
&lt;p&gt;&lt;/p&gt;
&lt;p&gt;&lt;/p&gt;

</description>
		<content:encoded><![CDATA[</p>
<p>
<h1><a href="http://seclists.org/pen-test/2009/Apr/0143.html">Re: Vulnerability vs. Pen test</a></h1>
</p>
<p>Posted by Ulises2k on Apr 24</p>
</p>
<p> Yes, <br /> Check this: <br /> <a href="http://blog.tenablesecurity.com/2007/07/pci-configurati.html" rel="nofollow">http://blog.tenablesecurity.com/2007/07/pci-configurati.html</a> <br /> <a href="http://pcianswers.com/2007/07/11/nessus-audit-files-and-uk-petitions-to-make-pci-law/" rel="nofollow">http://pcianswers.com/2007/07/11/nessus-audit-files-and-uk-petitions-to-make-pci-law/</a>  </p>
</p>
<p>URL: <a href="http://seclists.org/pen-test/2009/Apr/0143.html">http://seclists.org/pen-test/2009/Apr/0143.html</a></p></p>
]]></content:encoded>
	</item>
</channel>
</rss>

