2 cissp ® Official Study Guide Eighth Edition


Risks of Penetration Testing



Download 19,3 Mb.
Pdf ko'rish
bet716/881
Sana08.04.2023
Hajmi19,3 Mb.
#925879
1   ...   712   713   714   715   716   717   718   719   ...   881
Bog'liq
(CISSP) Mike Chapple, James Michael Stewart, Darril Gibson - CISSP Official Study Guide-Sybex (2018)

Risks of Penetration Testing 
A signifi cant danger with penetration tests is that some methods can cause outages. For 
example, if a vulnerability scan discovers that an internet-based server is susceptible to a 
buffer overfl ow attack, a penetration test can exploit that vulnerability, which may result in 
the server shutting down or rebooting. 
Ideally, penetration tests should stop before they cause any actual damage. 
Unfortunately, testers often don’t know what step will cause the damage until they take 
that step. For example, fuzz testers send invalid or random data to applications or systems 


770
Chapter 17 

Preventing and Responding to Incidents
to check for the response. It is possible for a fuzz tester to send a stream of data that causes 
a buffer overfl ow and locks up an application, but testers don’t know that will happen until 
they run the fuzz tester. Experienced penetration testers can minimize the risk of a test 
causing damage, but they cannot eliminate the risk. 
Whenever possible, testers perform penetration tests on a test system instead of a live 
production system. For example, when testing an application, testers can run and test the 
application in an isolated environment such as a sandbox. If the testing causes damage, 
it only affects the test system and does not impact the live network. The challenge is that 
test systems often don’t provide a true view of a production environment. Testers may be 
able to test simple applications that don’t interact with other systems in a test environment. 
However, most applications that need to be tested are not simple. When test systems are 
used, penetration testers will often qualify their analysis with a statement indicating that 
the test was done on a test system and so the results may not provide a valid analysis of the 
production environment.

Download 19,3 Mb.

Do'stlaringiz bilan baham:
1   ...   712   713   714   715   716   717   718   719   ...   881




Ma'lumotlar bazasi mualliflik huquqi bilan himoyalangan ©hozir.org 2024
ma'muriyatiga murojaat qiling

kiriting | ro'yxatdan o'tish
    Bosh sahifa
юртда тантана
Боғда битган
Бугун юртда
Эшитганлар жилманглар
Эшитмадим деманглар
битган бодомлар
Yangiariq tumani
qitish marakazi
Raqamli texnologiyalar
ilishida muhokamadan
tasdiqqa tavsiya
tavsiya etilgan
iqtisodiyot kafedrasi
steiermarkischen landesregierung
asarlaringizni yuboring
o'zingizning asarlaringizni
Iltimos faqat
faqat o'zingizning
steierm rkischen
landesregierung fachabteilung
rkischen landesregierung
hamshira loyihasi
loyihasi mavsum
faolyatining oqibatlari
asosiy adabiyotlar
fakulteti ahborot
ahborot havfsizligi
havfsizligi kafedrasi
fanidan bo’yicha
fakulteti iqtisodiyot
boshqaruv fakulteti
chiqarishda boshqaruv
ishlab chiqarishda
iqtisodiyot fakultet
multiservis tarmoqlari
fanidan asosiy
Uzbek fanidan
mavzulari potok
asosidagi multiservis
'aliyyil a'ziym
billahil 'aliyyil
illaa billahil
quvvata illaa
falah' deganida
Kompyuter savodxonligi
bo’yicha mustaqil
'alal falah'
Hayya 'alal
'alas soloh
Hayya 'alas
mavsum boyicha


yuklab olish