官术网_书友最值得收藏!

Status meeting and reports

Communication is key for a successful penetration test. Regular meetings should be scheduled between the testing team and the client organization and routine status reports issued by the testing team. The testing team should present how far they have reached and what vulnerabilities have been found up to that point. The client organization should also confirm whether their detection systems have triggered any alerts resulting from the penetration attempt. If a web server is being tested and a WAF was deployed, it should have logged and blocked attack attempts. As a best practice, the testing team should also document the time when the test was conducted. This will help the security team in correlating the logs with the penetration tests.

WAFs work by analyzing the HTTP/HTTPS traffic between clients and servers, and they are capable of detecting and blocking the most common attacks on web applications.
主站蜘蛛池模板: 江山市| 景谷| 江山市| 浑源县| 班戈县| 赫章县| 外汇| 吉安市| 荔浦县| 黄平县| 靖江市| 义马市| 贡山| 浮山县| 四会市| 蛟河市| 武夷山市| 渭南市| 和硕县| 大宁县| 公主岭市| 安福县| 嘉荫县| 宁河县| 渭南市| 博罗县| 金坛市| 翁牛特旗| 武邑县| 阳城县| 岗巴县| 孝感市| 岱山县| 新河县| 比如县| 池州市| 叶城县| 台州市| 德阳市| 南充市| 合肥市|