官术网_书友最值得收藏!

Scanning and enumeration

Without a doubt, almost every security professional wants to jump straight into exploiting boxes, but without understanding the basics, the exploits, and most importantly, the environment they are in. This can lead to mistakes or worse, such as breaking things in a live environment.

Scanning and enumeration allows a pen tester to understand their environment. The result one gets from these scans gives the red team a starting point to leverage vulnerabilities in different systems. Scanning is finding all available network services (TCP and UDP) running on the targeted hosts. This can help a red teamer discover whether SSH/Telnet is open to try a brute-force login and discover file shares to download data from, websites that may have vulnerabilities, or printers that may hold usernames and passwords. Enumeration is the discovery of services on the network to have a greater sense of information provided by the network services.

主站蜘蛛池模板: 延津县| 贡觉县| 舞阳县| 阿巴嘎旗| 台南市| 阳新县| 汤原县| 高邑县| 三门县| 裕民县| 如皋市| 治县。| 天峨县| 六枝特区| 岳池县| 双辽市| 开原市| 南华县| 进贤县| 温泉县| 宾川县| 轮台县| 肇庆市| 正阳县| 绥江县| 德保县| 林州市| 孟村| 峨山| 甘谷县| 温泉县| 苍山县| 昌图县| 华池县| 南靖县| 菏泽市| 陈巴尔虎旗| 龙江县| 大城县| 余庆县| 绍兴县|