Board logo

subject: Pen Testing - Defining The Grey Areas [print this page]


Pen Testing - Defining The Grey Areas
Pen Testing - Defining The Grey Areas

Pen Testing is about assessing how an organisation's network systems would hold up if they were infiltrated by a malicious attacker, also referred to as a Black Hat Hacker. A Pen Test also seeks to establish and/or what the consequences would be should a software failure occur. Typically a Whitebox Pen Test is used to uncover vulnerabilities and a Black Box Pen Test is used to develop security defences to counteract those vulnerabilities - A Grey Box Pen Test utilises and combines both these Network Security testing methods and techniques in a potent and prevailing way: Investigating any paths to the system which are immediately accessible from user inputs or external interfaces to the software.

The Contrasts

A Whitebox Penetration Test looks inside the "box" by using internal knowledge of that system. This would usually include access to source code and even passwords - In order to assess and validate both intended and unintended responses in a bid to uncover any vulnerabilities which could be maliciously exploited within that system. In stark contrast Black Box Pen Testing does not overtly use any data of the system's internal structure. Instead it focuses on testing the software's functional specifications and/or requirements from a Hackers viewpoint.

Why Grey?

The terms Whitebox and Black Box are routinely used: However, the terms "Structural Testing" and "Behavioural Testing" are also widely used. Whitebox Testing can be useful for highlighting any Network Security issues with regards to insider attack - Effectively what the consequences would be should someone with access to code and passwords use the information maliciously. Even so, no single Penetration Test technique or methodology has proven to be as useful as combining several: Hence working in the "Grey" is encouraged.

Grey Box Penetration Testing

Grey Box Testing effectively combines both black box testing and white box testing techniques - What clearly differentiates it from black box testing is that the IT security will have some knowledge of the internal systems being tested. During a Grey Box Penetration Test a restricted number of Whitebox tests are applied to the internal workings: After which black box techniques would be applied to observe the output of the software systems being tested.

Murray IT Security Services can provide a Pentest expert. Offering a range of IT Security Services our IT Security Experts can perform many levels of Pen Testing - White, Black and many areas of Grey. Our reports are informative and can help a Company ensure they are focusing their IT Security budget in the right areas; As well as keep their systems optimised and secure. Contact Murray IT




welcome to loan (http://www.yloan.com/) Powered by Discuz! 5.5.0