Don Parker Blog RSS

All Blogs  »  Don Parker Blog  »  Security Central  »  Blog article: Internal Pen-Test

Internal Pen-Test

Well having pen-tests performed against your network is now an accepted common practice. These can range from the fairly simple to rather complex. It all depends on the outbound facing services, and any backend databases that may be there as well. Not to mention the vagaries of the website itself. Unlike a malicious hacker I can without reservation use something like Nessus or Nikto as I have been legally retained to do the pen-test. Using one of these tools is akin to marching into church with a brass band ie: very, very noisy.

On the other hand I have also done what is less known; the internal pen-test. This is where as you would likely guess are performing a pen-test of the internal network. I would actually be on the inside of the network in the building itself to see what weaknesses can be exploited. Having such a test done is crucial as disenfranchised employees can wreak havok if your internal network is not hardened. Hmmmmmm, not a bad idea to write about actually. Do any of you have some thoughts on internal vs. external pen-tests???

Leave a Reply

This is a captcha-picture. It is used to prevent mass-access by robots. (see: www.captcha.net)

You must read and type the 5 chars within 0..9 and A..F, and submit the form.

  

If CAPTCHA image is missing or you cannot read the characters above, please generate a




Receive all the latest articles by email!

Receive Real-Time & Monthly WindowSecurity.com article updates in your mailbox. Enter your email below!
Click for Real-Time sample & Monthly sample

Become a WindowSecurity.com member!

Discuss your security issues with thousands of other network security experts. Click here to join!

Community Area

Log in | Register

Solution Center