An
Introduction to Penetration Testing There is no disputing facts...
the number of hacking and intrusion incidents is increasing year in year as technology
rolls out. Equally, there is no hiding place, you can be found through a variety
of means: DNS, Name Server Lookup, NSlookup, Newsgroups, web site trawling, e-mail
properties and so on. Whether the motivation is financial gain, espionage,
political, intellectual challenge, or simply trouble making, you may be exposed
to a variety of intruder threats. For these reasons, professional penetration
services are growing in popularity. Organizations are increasingly aware that
controlled security vulnerability testing is a major element in identifying exposures,
and ensuring that they are not exploited by a hostile party. The objective
of penetration testing is of course to investigate the system from the attacker's
perspective. The primary aim is to identify exposures and risk before seeking
a solution.  |  |  | | IP
PENETRATION TESTING | | DIAL-IN
TESTING | | Two
types of IP Penetration Tests are available - Evidential testing and testing performed
under the CHECK scheme. The latter tends to be employed for those who consider
themselves to be potentially greater targets for hostile parties, and is far more
structured and comprehensive than the former. | | Many
organization rely on dial-in systems, perhaps for traveling personnel, engineers
or even small office contact. Some also use dial-out for Internet access. Dial-in
covers both these systems, and embraces a number of distinct tests (including
modem testing and wardialling). | | INTERNAL
TESTING | | BESPOKE
TESTING | | Despite
the meteoric rise of hackers in the public consciousness and the very real increase
in the number of external attacks on company's websites and Internet connections,
reputable authorities such as the cert
still maintain that internal attacks are much more common. | | For
some customers, additional services are necessary. In addition, some attacks cannot
be included in a penetration test for legal reasons. If a client has a specific
security testing requirement, it is usually possible to identify a solution. |
|