官术网_书友最值得收藏!

Scanning and enumeration

Without a doubt, almost every security professional wants to jump straight into exploiting boxes, but without understanding the basics, the exploits, and most importantly, the environment they are in. This can lead to mistakes or worse, such as breaking things in a live environment.

Scanning and enumeration allows a pen tester to understand their environment. The result one gets from these scans gives the red team a starting point to leverage vulnerabilities in different systems. Scanning is finding all available network services (TCP and UDP) running on the targeted hosts. This can help a red teamer discover whether SSH/Telnet is open to try a brute-force login and discover file shares to download data from, websites that may have vulnerabilities, or printers that may hold usernames and passwords. Enumeration is the discovery of services on the network to have a greater sense of information provided by the network services.

主站蜘蛛池模板: 枝江市| 宽甸| 兰溪市| 遂宁市| 潞西市| 玉屏| 南涧| 敦煌市| 慈利县| 左权县| 屯门区| 郧西县| 屯昌县| 德保县| 阿尔山市| 漾濞| 遂昌县| 徐闻县| 琼中| 巫山县| 杭锦后旗| 新乡市| 开远市| 清徐县| 丰都县| 秦安县| 尚义县| 扶风县| 包头市| 陵川县| 海安县| 泰兴市| 漠河县| 浮山县| 文化| 荃湾区| 仲巴县| 余庆县| 潢川县| 溧水县| 台安县|