官术网_书友最值得收藏!

Myths and misconceptions of pen testing

After more than twenty years of performing professional security testing, I find it is amazing to know how many are confused about what a penetration test is. I have, on many occasions, been to a meeting and the client is convinced that they want a penetration test. However, when I explain exactly what one is, they look at me with a shocked look. So, what exactly is a penetration test? Remember our abstract methodology had a step for intrusive target search and part of that step was another methodology for scanning? Well, the last item in the scanning methodology, that being exploitation, is the step that is indicative of a penetration test. That one step is the validation of vulnerabilities, and this is what defines penetration testing. Again, it is not what most clients think when they bring a team in. The majority of them in reality want a vulnerability assessment. When you start explaining to them that you are going to run some exploit code and all these really cool things on their systems and/or networks, they usually are quite surprised. Most often, the client will want you to stop at the validation step. On some occasions, they will ask you to prove what you have found and then you might get to show the validation. I once was in a meeting with the stock market IT department of a foreign country, and when I explained what we were about to do with validation of vulnerabilities, the IT Director's reaction was "that is my stock broker records, and if we lose them, we lose a lot of money!". Hence, we did not perform the validation step in that test.

主站蜘蛛池模板: 出国| 梅州市| 新乐市| 宣恩县| 绵竹市| 广元市| 浦县| 衡山县| 原阳县| 天门市| 蒙城县| 凌源市| 长岭县| 沙雅县| 杭锦旗| 玉树县| 元谋县| 南宁市| 开化县| 松原市| 湘西| 通江县| 东辽县| 虎林市| 关岭| 澄江县| 洮南市| 庄河市| 山阳县| 中阳县| 新源县| 弥勒县| 莒南县| 绥芬河市| 页游| 增城市| 定西市| 鄂州市| 布拖县| 边坝县| 佳木斯市|