[Full-Disclosure] Pentesting an IDP-System

ph03n1x ph03n1x at gmx.net
Sat May 29 12:03:42 BST 2004


Hello

I'm kinda new to this list and this is my first post so be nice to me :)

Well I got an Intrusion Detection and Prevention System from a quite
famous company which they lend me for betatesting. I already compiled a
few exploits to test and it detected them quite reliable. (Didnt detect
the exploit but detected the shellcode)

Do you guys have an idea how i could test it more efficiently, is there
some software that automatically tries to attack with a bunch of the
most common and new exploits so i dont have to do it manually?
Preferably some GPL or other "free" stuff since i dont have a budget for
this.

What are the must criterias for an IDP would appreciate any links or
papers.


thx for tips

ph




Full-Disclosure is hosted and sponsored by Secunia.