官术网_书友最值得收藏!

White box pentesting

During white box pentesting, or what's sometimes named complete-knowledge testing, the organization gives the pentesters all required information. This type of pentesting is used when the organization wants to perform a full audit of its security and maximize the testing time. It can be done at any point to check its security position. The information provided before performing the pentesting could be, and it is not limited to the following things:

  • Network information: Network typology and diagrams, IP addresses, intrusion detection systems, firewalls, and access information
  • Infrastructure: Both hardware and software information is made available to the pentesters
  • Policies: This is really important because every pentester has to make sure that the pentesting methodology is aligned with the organization's policies
  • Current security state including previous pentesting reports
主站蜘蛛池模板: 怀集县| 武城县| 淮北市| 洛川县| 凌源市| 平和县| 临朐县| 信阳市| 元朗区| 民勤县| 百色市| 中方县| 南昌市| 宣武区| 永昌县| 嘉禾县| 乌兰浩特市| 南汇区| 巴彦县| 雅江县| 泰州市| 仲巴县| 苏尼特左旗| 广水市| 海兴县| 乐山市| 河北省| 齐齐哈尔市| 堆龙德庆县| 宣恩县| 措美县| 休宁县| 梅州市| 攀枝花市| 尖扎县| 屯留县| 侯马市| 东阳市| 札达县| 工布江达县| 潞西市|