官术网_书友最值得收藏!

Summary

Now that we have reached the end of this chapter, we should have everything that we need for the penetration test. Having had the scoping meeting with all the stakeholders, we were able to get answers to all the questions that we required. This included engagement questions and scoping criteria. A deliverable from the stakeholders after the scoping meeting should have included any documentation that you would find beneficial for the penetration test. We typically require a network diagram, organization chart, and any important data flow diagrams.

Once we completed the planning portion, we moved onto the preparation phase. In this case, the preparation phase involved setting up Kali Linux on both the Raspberry Pi as well as setting it up as a VM on the laptop. We went through the steps of installing and updating the software on each platform, as well as some basic administrative tasks.

In Chapter 2, Information Gatheringwe will start diving into the information gathering task. In this task, we will look at the various types of information to investigate, and where to look for additional information. We can't always rely on the stakeholder documentation being correct, and there may even be undocumented systems that even they don't know about. It is our job to find those systems. We will use various tools to get this information in order to help us understand the security and systems in place so that we know where to start the penetration tests later.

主站蜘蛛池模板: 满洲里市| 尼勒克县| 黑河市| 宁明县| 庐江县| 深泽县| 江陵县| 乌拉特前旗| 民勤县| 瓮安县| 西贡区| 尤溪县| 临颍县| 台安县| 重庆市| 邹城市| 株洲县| 安图县| 西乌珠穆沁旗| 彰化市| 安岳县| 望奎县| 铅山县| 青岛市| 威海市| 怀宁县| 兴业县| 周至县| 景洪市| 通州区| 吉木乃县| 洛阳市| 雷波县| 教育| 古蔺县| 四川省| 德安县| 旬阳县| 德令哈市| 江孜县| 绥阳县|