官术网_书友最值得收藏!

White box pentesting

During white box pentesting, or what's sometimes named complete-knowledge testing, the organization gives the pentesters all required information. This type of pentesting is used when the organization wants to perform a full audit of its security and maximize the testing time. It can be done at any point to check its security position. The information provided before performing the pentesting could be, and it is not limited to the following things:

  • Network information: Network typology and diagrams, IP addresses, intrusion detection systems, firewalls, and access information
  • Infrastructure: Both hardware and software information is made available to the pentesters
  • Policies: This is really important because every pentester has to make sure that the pentesting methodology is aligned with the organization's policies
  • Current security state including previous pentesting reports
主站蜘蛛池模板: 陇川县| 丹凤县| 白山市| 乐安县| 浙江省| 定襄县| 鄂温| 长岭县| 芦山县| 溧阳市| 巴楚县| 临湘市| 宁德市| 湟源县| 苏尼特左旗| 平顺县| 纳雍县| 慈溪市| 建昌县| 石楼县| 南阳市| 博野县| 高安市| 双柏县| 中卫市| 巢湖市| 阿瓦提县| 衡阳县| 酒泉市| 饶平县| 化德县| 雷州市| 黄陵县| 临城县| SHOW| 丰城市| 社旗县| 民乐县| 万荣县| 旬阳县| 泽库县|