- Penetration Testing Bootcamp
- Jason Beltrame
- 216字
- 2021-07-02 21:35:54
Scoping criteria
We will now see an example questionnaire for the scoping criteria. First, we will start with questions that will be derived from a white-box tester only to gain intimate knowledge of the network for testing:
- What are the subnets and/or IP addresses in the scope of this test?
- Are there any systems that are out of scope?
- Are there security devices within the network? (This is important because these devices may block access into an environment, and that will prevent testing the system correctly)
- Is there any type of important data held or transferred within the environment?
Finally, if the penetration tester is using more of a black-box mentality, then these questions will be relevant for them, as well as the white-box testers:
- Is guest access in scope as well?
- Which corporate SSIDs are in scope?
- What are the physical locations in scope for the test (if there are multiple locations)? Are all locations/networks dedicated, or are they shared with another company (for example, shared hosting or some cloud environments)?
This list is by no means complete or comprehensive. It is important for you, as a penetration tester, to figure out what questions you feel are relevant for your particular engagement. The preceding list contains some of the required questions, based on my experience.
推薦閱讀
- HornetQ Messaging Developer’s Guide
- 精通軟件性能測試與LoadRunner實戰(第2版)
- Learning Firefox OS Application Development
- 全棧自動化測試實戰:基于TestNG、HttpClient、Selenium和Appium
- 西門子S7-200 SMART PLC編程從入門到實踐
- Python High Performance Programming
- 編程與類型系統
- Microsoft Dynamics AX 2012 R3 Financial Management
- PHP編程基礎與實踐教程
- 編寫高質量代碼:改善Objective-C程序的61個建議
- 人工智能算法(卷1):基礎算法
- JSP程序設計與案例實戰(慕課版)
- OpenCV Android開發實戰
- 青少年Python趣味編程
- ANSYS FLUENT 16.0超級學習手冊