| |
Site Search
current news and information

Our Services - Penetration Testing

External Vulnerability Scanning is the traditional approach to penetration testing. The testing is focused on the servers, infrastructure and the underlying software comprising the target. It may be performed with no prior knowledge of the site (black box) or with full disclosure of the topology and environment (crystal box). This type of testing should typically involve a comprehensive analysis of publicly available information about the target, a network enumeration phase where target hosts are identified and analysed, and the behaviour of security devices such as screening routers and firewalls are analysed. Vulnerabilities within the target hosts should then be identified, verified and the implications assessed.

An Ethical Hack is designed to identify and assess threats to the organisation through bespoke, proprietary applications or systems. These applications may provide interactive access to potentially sensitive materials, for example. It is vital that they be assessed to ensure that, firstly, the application doesn't expose the underlying servers and software to attack, and secondly that a malicious user cannot access, modify or destroy data or services within the system. Even in a well-deployed and secured infrastructure, a weak application can expose the organisation's information assets to unacceptable risk.

 

© 2006 Security Heads Limited | Privacy Policy | Sitemap