Wednesday, October 5, 2011

Pre-engagement Interactions

The picture below shows all the pre-engagement activities:


NETWORK PENETRATION TEST
  1. Why is the customer having the penetration test against their environment?
  2. Is the pen test require for a particular compliance requirement?
  3. When does the customer wants you to execute the active parts of the pen test?
  4. What's the range of IP addresses? Are they internal? External?
  5. Are they security protections on the system? What are they?
  6. What if the penetration is succesful? Does the customer want you to try to escalate privileges, crack passwords?
WEB APPLICATION PENETRATION TEST
  1. How many web applications are being assessed?
  2. How many logins?
  3. How many static or dynamic pages?
WIRELESS NETWORK PENETRATION TEST
  1. How many wireless networks are there?
  2. Do they require an authentication?
  3. What type of encryption is used?
  4. How many clients will be using the wireless network?
PHYSICAL PENETRATION TEST
  1. How many locations are being assessed?
  2. How many floors are there?
  3. How many entrances are there?
  4. Are there guards?
  5. Are there video cameras?
SOCIAL ENGINEERING
  1. Will the client provide email addresses or phone numbers of personnel that we can attempt to social engineer?
  2. How many people will be targeted?
----------------------------------------------------------------------------------
  • Specify start and end date: this allows the project to have a definite end.
  • Specify IP ranges and Domain: you have to be sure that the target allowed you to perform the test. If after testing you discover that some IP don't belong to the pc owned by the customer it's too late.
  • Deal with Thirdy-parties: if a server is stored by using a hosting provider you'll need to be allowed to proceed also by the hosting provider.
  • DOS testing: be sure your customer allowed because stressing the network may cause important services to be inactive till the end of the test.
  • Emergency contact information: you'll need contacts you can use to communicate to your customer in case of emergency 24/7.
  • Encryption is not an option: since sensitive data is stored into the customer system all the tests has to be done using an encrypted session and communications such as emails must be encrypted, when it's possible choose face to face meetings.






2 comments:

umersiddique said...

welcome

umersiddique said...

what is engagement interaction in penetration testing

Post a Comment

 
Design by Free WordPress Themes | Bloggerized by Lasantha - Premium Blogger Themes | Affiliate Network Reviews