« Dinis Cruz midnight training session | Main | Working with Bundles with Ounce Labs »
Wednesday
30Sep2009

Be Careful with Custom Rules on client engagements

Consultants when working on client engagements be careful with custom rules with Ounce Labs.   If you are working on your own computer or a segregated network then it is fine, otherwise you should not mess with custom rules with a clients' Ounce Core.  I recommend using Ultra Edit and manually searching the code.     

 

 

For a use case we will use creating a custom rule to find credit card numbers and you were using security analyst on a client's system logging into a remote core with administrative credentials.    

 

If you updated that rule it would change the MAIN CORE affecting all other users of that CORE using Security analyst.     

 

 

Be careful of this, because it could damage your client's database and cost your client more than your billable rate. Does anyone disagree or have any arguments to this point?     

 

Reader Comments

There are no comments for this journal entry. To create a new comment, use the form below.

PostPost a New Comment

Enter your information below to add a new comment.

My response is on my own website »
Author Email (optional):
Author URL (optional):
Post:
 
Some HTML allowed: <a href="" title=""> <abbr title=""> <acronym title=""> <b> <blockquote cite=""> <code> <em> <i> <strike> <strong>