Wednesday, 18 April 2012

What Is Penetration Testing And Example


Penetration testing (also called pen testing) is the practice of testing a computer system, network or Web application to find vulnerabilities that an attacker could exploit.
Pen tests can be automated with software applications or they can be performed manually. Either way, the process includes gathering information about the target before the test (reconnaissance), identifying possible entry points, attempting to break in (either virtually or for real) and reporting back the findings.



The main objective of penetration testing is to determine security weaknesses. A pen test can also be used to test an organization's security policy compliance, its employees' security awareness and the organization's ability to identify and respond to security incidents.

Penetration tests are sometimes called white hat attacks because in a pen test, the good guys are attempting to break in.

Pen test strategies include:


Targeted testing
Targeted testing is performed by the organization's IT team and the penetration testing team working together. It's sometimes referred to as a "lights-turned-on" approach because everyone can see the test being carried out.

External testing
This type of pen test targets a company's externally visible servers or devices including domain name servers (DNS), e-mail servers, Web servers or firewalls. The objective is to find out if an outside attacker can get in and how far they can get in once they've gained access.

Internal testing
This test mimics an inside attack behind the firewall by an authorized user with standard access privileges. This kind of test is useful for estimating how much damage a disgruntled employee could cause.

Blind testing
A blind test strategy simulates the actions and procedures of a real attacker by severely limiting the information given to the person or team that's performing the test beforehand. Typically, they may only be given the name of the company. Because this type of test can require a considerable amount of time for reconnaissance, it can be expensive.

Double blind testing
Double blind testing takes the blind test and carries it a step further. In this type of pen test, only one or two people within the organization might be aware a test is being conducted. Double-blind tests can be useful for testing an organization's security monitoring and incident identification as well as its response procedures.

Tuesday, 17 April 2012

Contoh-Contoh Pen-Test Linux Distributions

Apakah Pen-Test Linux Distributions yang anda kenali? Tentu sahaja jawapan yang biasa didengari adalah BackTrack... Ada juga yang kata saya guna BackTrack sebab saya hacker.. Hang hacker ke? Adakah anda cukup mahir mengendalikan tools pentest yang ada dalam BackTrack tu? Tepuk dada tanya hati...


Disini beberapa contoh Linux Pentest selain daripada BackTrack...


1. BackBox Linux 2.01


Klik link ini untuk membaca lebih lanjut :

2. Node Zero


Klik link ini untuk membaca lebih lanjut :

3. Knoppix STD


Klik link ini untuk membaca lebih lanjut :

4. Blackbuntu 0.3


Klik link ini untuk membaca lebih lanjut :

5. Pentoo


Klik link ini untuk membaca lebih lanjut :

6. Samurai Web Testing Framework


Klik link ini untuk membaca lebih lanjut :

7. Matriux Krypton v1.2 (Nullcon 2012)


Klik link ini untuk membaca lebih lanjut :

8. WEAKERTH4N Linux Version 3.6 BETA


Klik link ini untuk membaca lebih lanjut :

Saturday, 14 April 2012

Cara Install Conky Untuk BackTrack 5 R1-R2

Buka Terminal Anda


Taip :


apt-get install conky


conky


Plug-In Disable

Assaalammualaikum,

Memandangkan terasa berat nak load blog saya dah disable plugin jquery loader yang saya pakai sebelum ini, memang terasa berat sangat nak pakai benda tu sampai saya sendiri tak dapat view blog sendiri dengan berukband yang dah habis tempoh ini.

Kira-kira nak try simcard yang sekali bayar je tu, celcom pumya lah... ada dealer yang boleh dipercayai ke?

Wasalam.

Alhamdullillah


Assalammualaikum,


Terasa lama sangat saya tak buka blog ne, sejak-sejak blog ne tak dapat di akses, entah tetiba malam ne terasa nak try akses dan alhamdullillah blog saya dah dapat dibuka semula.


Bengong punya blogspot suka-suka hati je block blog aku, aku taulah aku guna free je.. Haram Jadah...


Wasalam And Selamat Malam :)