Penetracijsko testiranje

Izvor: SIS Wiki
Skoči na: orijentacija, traži

Osnove:


Mogući izvori napada:


TTP (time-to-patch):


Motivacija:


Korisno:


Auditing and Recon:

http://nmap.org/

http://www.paterva.com/web5/

http://www.google.com

https://sudreg.pravosudje.hr/

http://rgfi.fina.hr/JavnaObjava-web/jsp/prijavaKorisnika.jsp


Google hacking databases:

http://www.hackersforcharity.org/ghdb/

http://www.exploit-db.com/google-dorks/

http://www.ifac.org/sites/default/files/meetings/files/1831.pdf

Exploit Database:

http://www.exploit-db.com/

Frameworkovi:

http://www.metasploit.com/

http://www.tenable.com/products/nessus

http://www.openvas.org/

Web security:

http://cirt.net/nikto2

http://w3af.sourceforge.net/

http://sqlmap.sourceforge.net/

Pentesting methodology:

http://csrc.nist.gov/publications/PubsSPs.html

http://www.pentest-standard.org/index.php/Main_Page

http://www.isecom.org/research/osstmm.html

Osobni alati
Imenski prostori
Inačice
Radnje
Orijentacija
Traka s alatima