官术网_书友最值得收藏!

Planning and reconnaissance

In the planning and reconnaissance phase, we define the scope of the penetration test. This initial phase requires a lot of planning, and you need to answer questions, such as:

  • What is the scope of the pentest?
  • What are the restricted URLs?
  • What are the various subdomains in scope?
  • Are there multiple applications hosted on the same domain in different folders?
  • Are there any other platforms where this application is hosted (that is, mobile applications, web applications, desktop applications, and so on)

Once you have answered these questions, you will get some clarity on what is to be tested and what's not. Depending on whether it is a black box or a white box test, further enumeration takes places. In either of the cases, we will have to go ahead and discover all the files and folders of the application in scope and identify the endpoints. Later, in the next chapter, we will see how to discover new files and folders using Burp.

主站蜘蛛池模板: 阳东县| 颍上县| 衡山县| 康乐县| 青海省| 平度市| 波密县| 新竹市| 三河市| 安丘市| 漾濞| 闽侯县| 上林县| 红河县| 大同市| 樟树市| 靖西县| 南丰县| 定南县| 蛟河市| 乐安县| 嫩江县| 古田县| 澳门| 台南县| 华亭县| 大名县| 庄河市| 卓资县| 丹凤县| 文登市| 克什克腾旗| 丹棱县| 宾阳县| 杭锦后旗| 云林县| 上栗县| 新巴尔虎左旗| 海伦市| 浦东新区| 定州市|