官术网_书友最值得收藏!

Penetration testing

The penetration test is an authorized attack against an information system which is used to simulate a real attack that could be perpetrated by a black hat hacker.

Penetration testing is a very important part of the information security program and is needed in order to find hidden vulnerabilities in the information system. Many organizations implement vulnerability assessment tools but do not add penetration testing to their overall testing methodology. Penetration testing is important because it allows the information security program to uncover vulnerabilities that are not easily captured through automated means. The penetration tester takes their information security knowledge and uses it to systematically break into an information system even when a vulnerability scanner has not found a vulnerability present.

Remember that there are various levels of penetration testing:

  • Those that are fully engaged and coordinated with your business and its operations personnel
  • To red team penetration testing, which is the same as a black hat

Also, remember that penetration testing covers a full array of activities that include:

  • Physical security test
  • Network intrusions
  • Social engineering, and so on

A penetration testing engagement from a white hat / ethical hacker can include services such as:

  • Collecting trash from trash cans and dumpsters in order to look for passwords and intellectual property
  • Pretending to be the organization's helpdesk in an attempt to retrieve user passwords
  • Social engineering attacks such as phishing and spear phishing attacks
  • Web-based application attacks
  • Vulnerability scanning
  • Port scanning and so on
主站蜘蛛池模板: 衡水市| 江西省| 长泰县| 平顺县| 安远县| 唐山市| 泸州市| 林口县| 精河县| 正镶白旗| 青冈县| 文登市| 固原市| 白银市| 杨浦区| 彭泽县| 洪湖市| 临泽县| 龙川县| 文成县| 巴彦淖尔市| 马尔康县| 海盐县| 洛南县| 陆川县| 长沙县| 通道| 镇康县| 连江县| 平邑县| 长汀县| 宁阳县| 崇信县| 资讯 | 任丘市| 新竹市| 明水县| 揭东县| 和平县| 林西县| 新余市|