官术网_书友最值得收藏!

Types of penetration tests

Whenever a penetration tester is assigned to simulate real-world attacks against a target organization, there are usually one of three types of penetration tests conducted: white box, grey box, and black box. Each type will determine what assets are exposed to both an insider threat and an external party, such as a black hat hacker.

A white box test is an easy type of penetration test as a complete knowledge of the target’s systems and network is known prior to the simulated attack. This can be beneficial to the penetration tester as they would have ample information about the target network and can better utilize tools and resources in creating, delivering, and executing payloads that would most likely be successful on the first attempt. However, there is a disadvantage to this type of penetration test. The ethical hacker or penetration tester most likely won’t be looking for any hidden vulnerabilities and systems outside the knowledge that was provided prior to the testing,or for the complete knowledge of the infrastructure of the system.

Black box testing is where no information or knowledge is given to the penetration tester about the target systems or infrastructure. The penetration tester will behave like an actual black hat hacker to gain access into the target. The only information given is sometimes the company’s name or just the website. The ethical hacker or penetration tester will need to do all the hard work to determine the type of organization and its industry, the type of networking and security appliances are within the network infrastructure, its employees, and so on.

Grey box testing is somewhere between white box and black box penetration testing. The penetration tester is give very limited information about the target infrastructure prior to the actual security audit or penetration test.

主站蜘蛛池模板: 新乡县| 喜德县| 莱西市| 茂名市| 泗阳县| 灯塔市| 吴川市| 黄骅市| 古蔺县| 云和县| 山东| 丹江口市| 中宁县| 灵璧县| 古蔺县| 呈贡县| 定陶县| 寿宁县| 德阳市| 八宿县| 湾仔区| 娱乐| 庆云县| 竹溪县| 乐都县| 嘉祥县| 公安县| 邵武市| 东山县| 绥中县| 德钦县| 苗栗县| 鄂伦春自治旗| 上饶市| 项城市| 乐陵市| 历史| 马关县| 余干县| 天水市| 临洮县|