CSOinformer
Volume 1, Number 12
August 12, 2003
Edited by Jim Reavis
jim@csoinformer.com
"Welcome to CSOinformer, the monthly newsletter briefing for information security professionals. The analysts with CSOinformer stand ready to help you with leading edge information security research and advice."
Under the Radar - Resume-based Network Mapping
At the recent Black Hat Briefings in Las Vegas, I attended a session about new methodologies for penetration testing, called “Modern Intrusion Practices” by Gerardo Richarte of Core Security Technologies. While many practices were discussed, one thing that immediately resonated with me was increasing the scope of targets and the concept of using indirect targeting as well. In other words, if your ultimate target is a well-protected strategic host, instead of directly attacking it, figure out how to compromise the people who have access to and potentially even administer it. It could very well be that the system administrator’s desktop or home PC provides an easier intermediate target that helps you reach the ultimate goal.
.::Click on the











