- Penetration Testing Bootcamp
- Jason Beltrame
- 216字
- 2021-07-02 21:35:54
Scoping criteria
We will now see an example questionnaire for the scoping criteria. First, we will start with questions that will be derived from a white-box tester only to gain intimate knowledge of the network for testing:
- What are the subnets and/or IP addresses in the scope of this test?
- Are there any systems that are out of scope?
- Are there security devices within the network? (This is important because these devices may block access into an environment, and that will prevent testing the system correctly)
- Is there any type of important data held or transferred within the environment?
Finally, if the penetration tester is using more of a black-box mentality, then these questions will be relevant for them, as well as the white-box testers:
- Is guest access in scope as well?
- Which corporate SSIDs are in scope?
- What are the physical locations in scope for the test (if there are multiple locations)? Are all locations/networks dedicated, or are they shared with another company (for example, shared hosting or some cloud environments)?
This list is by no means complete or comprehensive. It is important for you, as a penetration tester, to figure out what questions you feel are relevant for your particular engagement. The preceding list contains some of the required questions, based on my experience.
推薦閱讀
- 深入理解Bootstrap
- Computer Vision for the Web
- Twilio Best Practices
- C語言程序設計
- PHP 編程從入門到實踐
- PostgreSQL 11從入門到精通(視頻教學版)
- CKA/CKAD應試教程:從Docker到Kubernetes完全攻略
- HTML5+CSS3網站設計基礎教程
- INSTANT Django 1.5 Application Development Starter
- Oracle 18c 必須掌握的新特性:管理與實戰
- Mastering Unity 2D Game Development(Second Edition)
- Learning Continuous Integration with TeamCity
- 編程改變生活:用Python提升你的能力(進階篇·微課視頻版)
- QPanda量子計算編程
- Java 從入門到項目實踐(超值版)