Security Testing


We have discussed the channels of testing in the previous discussion; here we will focus on the testing approach or methodology. Security testing has been addressed in the context of software development for quite sometime. In the context of ethical hacking, the security professional has to conduct a security evaluation and test the system for vulnerabilities. This can be approached in different ways.
The concept of black-box testing is based on the assumption that the ethical hacker has no prior knowledge or information about the system. In this sense, black-box testing simulates a true web-hacking attack, beginning with nothing but the organization's corporate name. From here the ethical hacker gathers information about the network and the business from as many outside sources as possible. This can include publicly available information from sources such as web sites and media publications that contain useful information about the business. Social engineering techniques may also be used where information is gathered from unsuspecting employees. This aspect will be dealt in detail in later modules. This is similar to the reconnaissance phase that a malicious attacker would carry out prior to an attack. This gives the ethical hacker an idea of all possible security lapses including policy level lapses.
The ethical hacker then uses scanning tools such as port scanners to aid him in network mapping. The ethical hacker begins probing the network for exploitable vulnerabilities based on a network map created from the initial investigation. This is exactly like the scanning phase of a hack attack. The ethical hacker does everything that a hacker does. Exploiting vulnerabilities is an important part of a penetration test. The ethical hacker tries to exploit them in such a way that they do not cause damage however, sometimes they do. This is taken care of in the legal paperwork drawn during the rules of engagement. While attacks such as denial of service attacks do not have a place in a penetration test; actually breaking in has to be done in most cases to demonstrate the true impact of vulnerabilities discovered. In addition, the ethical hacker recommends counter measures to patch the security hole.
The concept of white-box testing on the other hand is based on the assumption that the ethical hacker knows the system and has full access to system related information. Nevertheless, white-box testing has fundamental similarities in terms of the testing involved. The ethical hacker is given full access to information about the client's organization and network infrastructure from the outset. The ethical hacker has access to all system design and implementation documentation, which may include listings of source code, manual and circuit diagrams. This helps the ethical hacker adopt a structured and formal approach. However, a good ethical hacker will also test the validity of the information provided initially, rather than work under the assumption that it is true.
It is considered by some security experts that the black-box testing closely imitates a real web based attack. However, this need not hold good as script kiddies can easily know details of the operating systems and run scripts to exploit vulnerabilities. More often than not, the hacker is no total stranger to the system. He has access to insider information or may even be an insider. Many organizations are subject to attack from internal sources where full systems knowledge can be assumed.
Another aspect to be considered while testing is that hackers are known to have great patience and immense determination. They may plan and phase their attacks over months which are not the case with an ethical hacker who uses a predetermined methodology to fit inside the time constraint. This methodology can be common knowledge and hence, it may miss out on vulnerabilities that a hacker may otherwise notice.
It is imprudent to assume that a hacker would not adopt a structured approach, and will not continue probing over time until a system is compromised. This is especially true if an organization has external networks which are not publicly listed, as these will not show up at the information gathering stage in a black-box testing and will therefore not be tested. Hackers can stumble across unlisted networks using random scanning techniques and exploit potential vulnerabilities. It must be remembered that any computer connected to the Internet is typically scanned several times a day as hackers search for systems they can compromise.
There is another consideration that comes into play while choosing a method for testing. This is value for money. If monetary resources and time are a constraint, black box testing may not be the best option. This is where an organization may consider internal testing. Also known as grey-box testing, this allows system administrators and network professionals to take time and resources to test the system and detect vulnerabilities. This is called grey box testing because it is quite possible that they are known and unknown aspects of the system.
In short, all forms of security testing can be of value to an organization; however, it is up to the organization to decide what works in its best interests under the given circumstances. A black-box test may highlight how supposedly confidential information is leaked, while a white-box test is likely to dedicate much more time to probing for vulnerabilities and will address the security of all external connections. In security terms, it is more prudent to assume the worst when testing a network, thus addressing all potential vulnerabilities and weaknesses. The case for ethical hacking lies here, as it should be assumed that a hacker does have a full knowledge of the network infrastructure, because if security relies solely on its secrecy then it is as good as nonexistent.

COMMENTS

Name

©2012 Oceninfo.co.cc,2,10:29 IST,1,2012,1,Adfly Bot,2,AFCEH,1,Ajax security,1,all posts for education purpose only...www.facebook.com/princebhalani,1,Android,1,android developer,1,android phone,1,android phone-1,1,anonymous email,1,Anti-Trojan software,8,Antivirus,1,Apple,1,article marketing,1,at risk,1,attacks,1,australian federal police,1,Auto Clicker,1,Auto surfer,1,backtrack link,2,Bank Hacking,2,BCMSN,2,BIOS Update,1,Blockchain,1,Blog and tagged Ransomware,1,boot fast...,1,boot xp faster,1,Business Deals,1,Bypass Antivirus and Hack Window Systems,1,CCIE,2,CCNA,2,CCNP,2,CEH,2,challenge-response system,1,Changing Root Bridge Election Results,2,code,2,commands,1,company deals,1,Computer Hacking,3,Connect,1,cookie stealing,3,Country,1,Crack,1,Credit Card Fraud,2,credit cards,1,Cryptography,1,cyber cell updated,1,cyber security,1,DATA CARD TRICK,1,delhi,1,Digital Marketing,1,direct admission in any colleges,2,Direct Link,3,Directory Traversal Attacks,1,Dos and Ddos,1,DotNetNuke Remote File Upload Vulnerability,1,Earn Lots of money,3,EARN MONEY PART2,1,earnings in$,1,email hacking,4,email spoofing,2,Er Prince Bhalani jobs,1,Ethical Hacker job,1,ethical hacking,8,exploit,1,facebook autoliker,1,Facebook tricks,3,Fake Mail,1,fake sms,1,FB hackz,1,FBI,1,FBI HACKERS,2,FBI Jobs,2,featured,6,Finger scan,1,fingerprint Hacking,1,format without pain,1,Free Download,1,Free Flash Templates,1,free hacking book,5,Free Recharge,1,free sms,2,Freebeacon,1,friendship day,2,friendship day image,2,friendship image,1,Future Computer,2,future of hacking,1,Gadgets,1,good clean fun,1,google,3,Google Ads,1,google adsense account,1,Google hacking,3,google hacks,1,google search,1,hack,2,hack the world,2,HACK WEBSITES USING SQL INJECTION,2,hacker,1,hacker uni,1,hacker/LPT/etc,1,hackers,2,Hackerz info,1,hacking,4,hacking games,1,hacking matterial,1,HACKING OFER,1,hacking softwares,1,hacking tools,2,Hacking with Mobile phones,1,HackingTeacher Security Solutions,1,hacks,1,hijack,1,history of hacking,1,How to,8,How to Hack,37,how to play,1,How to sniff,1,html,1,HTTPS/SSL secured sites,1,I LOVE YOU VIRUS,1,i-phone hacking,1,ICITAM 2012,1,iCloud Era,1,In Flow,1,indian cyber cell,4,information security,1,interesting,1,inurl:fcklinkgallery.as,1,IP hacks,1,iphone,1,IT Act,1,IT Decision Maker,1,IT Implem_App/LOB Spec,1,IT Implem_Desktop/EndUser Spec,1,IT Implem_Infrastructure Spec,1,IT Implem_IT Generalist and IT Manager.,1,it security,1,java,1,jobs for ethical hacker,3,jobs in hacking,5,Joe job,1,Just for education purpose only,1,Kaspersky,1,kaspersky crack 2013,1,keyboard hacking,1,keyloggers,1,keywords,1,Laptop Tracking,1,Laws of computer crime,1,Learn Cracking,1,Learn Website Hacking,7,Linkbucks Bot,1,Macromedia Flash,1,make some rules...|||_|||,1,malicious code,1,Malware,1,malware analysis,1,man in the middle attack (LAN),1,master,1,master list,1,metasploit,3,Microsoft scams,1,mobile,1,mobile recharge,1,moblie phone hacking,1,munging,1,network hack,1,Network Sniffers,1,new command set,1,new projects,1,nmap,1,No Survey,1,not infrequent,1,online scanners,1,paisa live hack,1,panetration for educational purpose only,1,Parental Controls,1,password hacking,4,Password sniffing with arp poisoning,1,PC TIPS,1,PE_PARITE (Trend Micro),1,penetration testing,1,pharming,1,phishing,1,phone hacking charged,1,PHP,1,pin ball,1,Play WMV Files,1,Press Trust of India / New Delhi Aug 15,1,Prime minister,1,prince bhalani,1,princebhalani,1,Professional job in FBI,1,Professional Penetration Testing,1,Programming,1,Programming of virus,2,protect my pc against hackin,1,proxy list by http,1,Proxy SOCKS Port,1,R-Admin With Key,1,Radmin,1,RAW Jobs,1,Real Hackers vs fake ethical hackers. ..:),1,Register of Known Spam Operations (ROKSO),1,repair corrupt hard disk,1,RFT,1,Robbery,1,Rupert Murdoch,1,SAMPLE,1,Sample dynamic flash template from TM website,1,Scams,2,Scanned Vulnerabilities,1,SEA,2,search engine hacking,1,Search Operators,1,Security,2,Security breach,1,security code brack,1,SEM,4,SEO,112,SEO Mistakes,1,SEO TOOLS,1,SEO Tricks,3,SERM,1,SERP,1,Session Hijacking,4,SET,1,shell commands...,1,shell list with download,1,SITES,1,Smart Home,1,Smartphones,1,SMM,1,SMO,2,sms spoofing,1,SMTP Servers,1,Sniffing passwords,1,Sothink SWF Decompiler,1,spam cocktail (or anti-spam cocktail),1,spam trap,1,spear phishing,2,SQL hacking,2,SQL Injection Attacks by Example,2,SSL,1,SSL Analysis,1,starting of help,1,System Information,1,System Restore,1,Tablet in 1000,1,Tablets,1,Temporary Email Service,1,time need,1,timer,1,tracing,1,Traffic,3,tricks,5,Tricks and Tips,1,Trojan,1,Trojan tools,1,Trojans and Backdoors,2,trojon,7,Turbo C++,1,UK phone hacking,1,UK phone hacking arrest,1,USA JOBS,4,Virus,2,virus writing,2,VPN,1,vulnerabilities,1,vulnerability assessment,1,W32/Pate (McAfee),1,W32/Pinfi (Symantec),1,Washington,2,web hacking,6,web security,1,Website Development,1,Website Hacking,3,White House,1,wifi hacking,3,Win32 : parite (Avast),1,Win32.Parite (Kaspersky),1,Win32/Parite,1,windows,2,Windows 8 event for IT Professionals,1,wirless hack,1,WordPress,1,WordPress hacking,1,working with Virus and worm,9,XP Hacking,1,xp hacking-1,1,XP part 3,1,xss hacking,1,
ltr
item
Group Of Oceninfo: Security Testing
Security Testing
Group Of Oceninfo
https://oceninfo.blogspot.com/2011/09/security-testing.html
https://oceninfo.blogspot.com/
https://oceninfo.blogspot.com/
https://oceninfo.blogspot.com/2011/09/security-testing.html
true
6415817773321450103
UTF-8
Loaded All Posts Not found any posts VIEW ALL Readmore Reply Cancel reply Delete By Home PAGES POSTS View All RECOMMENDED FOR YOU LABEL ARCHIVE SEARCH ALL POSTS Not found any post match with your request Back Home Sunday Monday Tuesday Wednesday Thursday Friday Saturday Sun Mon Tue Wed Thu Fri Sat January February March April May June July August September October November December Jan Feb Mar Apr May Jun Jul Aug Sep Oct Nov Dec just now 1 minute ago $$1$$ minutes ago 1 hour ago $$1$$ hours ago Yesterday $$1$$ days ago $$1$$ weeks ago more than 5 weeks ago Followers Follow THIS CONTENT IS PREMIUM Please share to unlock Copy All Code Select All Code All codes were copied to your clipboard Can not copy the codes / texts, please press [CTRL]+[C] (or CMD+C with Mac) to copy