官术网_书友最值得收藏!

Managing collaborative penetration testing using Faraday

One of the most difficult aspects of penetration testing is remembering to test all of the relevant parts of the network or system target, or trying to remember whether the target was actually tested. In some cases, a single client may have multiple penetration testers performing scanning activities from multiple locations and management would like to have a single view. Faraday can provide a single view, assuming all the penetration testers are able to ping each other on the same network, or on the internet for external assessment.

Faraday is a multiuser penetration test Integrated Development Environment (IDE). It is designed for testers to distribute, index, and analyze all the data that is generated during the process of a penetration testing or technical security audit to provide different views such as management, executive summary, and an overall issues list.

This IDE platform is developed in Python by InfoByte. Download the application from https://github.com/infobyte/faraday/wiki or directly git clone the link, as shown in the following screenshot:

Once the folder is cloned to your Kali, run ./install.sh to install any dependencies. Do not forget to start the CouchDB service, as Faraday utilizes CouchDB as its database for storage. Finally, we run faraday-server.py to launch the Faraday server for an integrated platform, and then as the client, we should be able to launch Faraday by running faraday.py, as shown in the following screenshot:

Launching Faraday should open up the Faraday shell console to us, as shown in the following screenshot:

One positive aspect of the application is that you will be able to visualize the information from any scanning that you do, or that any other penetration tester does, by clicking on Faraday web, as shown in the following screenshot:

There is a limitation on the free version of Faraday for the community, which can be utilized to visualize all the lists of issues in a single place.

主站蜘蛛池模板: 怀宁县| 黎川县| 开平市| 齐河县| 大关县| 武强县| 株洲市| 岑巩县| 武功县| 民勤县| 宜兰市| 临夏市| 班玛县| 清镇市| 浦北县| 靖西县| 盘山县| 太仆寺旗| 阿拉善右旗| 裕民县| 景泰县| 陇川县| 淮阳县| 宁海县| 彩票| 措勤县| 凌源市| 象州县| 深泽县| 鄱阳县| 凤山县| 叶城县| 南皮县| 温州市| 收藏| 漠河县| 霍山县| 崇州市| 油尖旺区| 桂平市| 盈江县|