官术网_书友最值得收藏!

White box pentesting

During white box pentesting, or what's sometimes named complete-knowledge testing, the organization gives the pentesters all required information. This type of pentesting is used when the organization wants to perform a full audit of its security and maximize the testing time. It can be done at any point to check its security position. The information provided before performing the pentesting could be, and it is not limited to the following things:

  • Network information: Network typology and diagrams, IP addresses, intrusion detection systems, firewalls, and access information
  • Infrastructure: Both hardware and software information is made available to the pentesters
  • Policies: This is really important because every pentester has to make sure that the pentesting methodology is aligned with the organization's policies
  • Current security state including previous pentesting reports
主站蜘蛛池模板: 西青区| 邹城市| 渝中区| 盘山县| 廉江市| 洛宁县| 金堂县| 安乡县| 清水县| 和静县| 天峨县| 山西省| 彝良县| 广宗县| 广宁县| 南郑县| 临泽县| 武定县| 南江县| 洛南县| 儋州市| 寻乌县| 赣州市| 东海县| 连江县| 吉水县| 通榆县| 东宁县| 芜湖市| 彩票| 洛浦县| 吐鲁番市| 任丘市| 墨江| 岚皋县| 溧阳市| 青铜峡市| 伊吾县| 南阳市| 敦煌市| 许昌市|