Penetration testing Flashcards
What is penetration testing?
This is testing a organizations resistance to external attacks, by exploiting vulnerabilities in the security systems.
What is white box testing?
This is operated as and insider threat, knowing such as platform systems configuration, opearting system, hardware
What is black box testing?
This is done by a external threat view less knowledge of the environment and requires recon and discovery, ideally testers should have similar skill levels as the attackers you might have
what is gray box testing?
This is middle of the road approach that borrows from both black/white box , this could be done for time constraints, or testing a certain system
What are the rules of engagment?
Defines the parameters of the test, scoping of the when and what, also gives a timeline for the test, and lastly when the test will proceed and set the legal concerns. As well as third party concerns
Phases of penetration testing
Recon>Initial access>privilege escalation>Pivoting/lateral movement>Maintain persistence>Reporting>Cleanup
Penetration testing - cleanup
Closing out penetration test, putting everything back the way it was
what are bug bounties?
Its responsible disclosure programs, this is outside testing, and help discover vulnerabilities, and provide incentive to testers