Core Security
info@coresecurity.com  | +1.617.399.6980 | Contact Us   Core Blog Core Blog Twitter LinkedIn youtube
News
SHARE
Pen Tests Find and Patch Network Openings

By Carl Weinschenk

Excerpt:

“We view vulnerable scans and penetration tests as complementary technologies. They are not at all competitive. If you look at a building and look at all the windows, a vulnerability scan would say, I think windows on the first floor and the seventeenth are open. I haven’t actually tried to open those windows, but they look like they might be open. Vulnerability scanners may say because the window on the first floor is easily accessible, it is critical, so you should check that one first. This is all based on probability. Nothing has been attempted yet. Penetration tests try to open the windows to confirm or refute the fact of what the vulnerability test finds. In cases in which the first-floor window is open but leads to a locked janitor's closet, it's not [a problem] anyway. But suppose the seventeenth floor is unlocked and happens to be the office of the administrative assistant to the CEO who has access to all the CEO's files. Penetration test against that tries to physically enter the system to assess the situation.”


Source:  IT Business Edge

View the full article

Related Content