Attack and Penetration Test Plan

User Generated

wbpxrl4rire

Computer Science

Description

Scenario:

You are the owner and operator of a small information security consulting firm. You have received a request from one of your clients, Infusion Web Marketing, to provide a written proposal for performing a penetration test on the company's production Web servers and corporate network.

Environment:


Scope

Production e-commerce Web application server, the e-commerce Web application server is acting as an external point-of-entry into the network:
• Ubuntu Linux 16.04 LTS Server (TargetUbuntu01)
• Apache Web Server running the e-commerce Web application server
• Credit card transaction processing occurs on all web servers

Intrusive or Non-Intrusive

Intrusive. The test will include penetrating past specific security checkpoints.

Compromise or No Compromise

No compromise. The test can compromise with written client authorization only.

Scheduling

Between 2:00 a.m-6:00 a.m. weekend only (Saturday or Sunday)

Deliverables:

Using the information from the scenario above, provide a written attack and penetration testing plan, describing your firm's approach to performing the penetration test and what specific tasks, deliverables, and reports you will complete as part of your services. The plan should include these sections:

  1. Table of Contents
  2. Project Summary
  3. Goals and Objectives
  4. Tasks
  5. Reporting
  6. Schedule

Your penetration testing plan should be 4-5 pages in length, not including the title and references pages, and cite at least four credible sources other than the course materials. It should follow University academic writing standards and APA style guidelines, as appropriate.

It is strongly encouraged that you submit all assignments to the Turnitin Originality Check prior to submitting.


Helpful Resources:

Course textbook: http://index-of.es/Hack/HackerTechniquesTools.pdf

The SANS Institute provides several resources that you might find helpful for this assignment: http://www.sans.org/reading-room/whitepapers/testing

The National Institute for Standards and Technologies (NIST) also provides some guidance on this topic: http://csrc.nist.gov/publications/nistpubs

User generated content is uploaded by users for the purposes of learning and should be used following Studypool's honor code & terms of service.

Explanation & Answer

Attached.

Running head: INFUSION WEB MARKETING PENETRATION TESTING PROPOSAL 1

Infusion Web Marketing Penetration Testing Proposal
Names:
Institution:

INFUSION WEB MARKETING PENETRATION TESTING PROPOSAL

2

Contents
Infusion Web Marketing penetration testing proposal .......................................................................... 3
Penetration testing project summary ..................................................................................................... 3
Goals and objectives................................................................................................................................ 4
Tasks ........................................................................................................................................................ 5
Network reconnaissance ..................................................................................................................... 5
Network vulnerability testing .............................................................................................................. 5
Web server Vulnerability testing ......................................................................................................... 6
Reporting ................................................................................................................................................. 6
Schedule .................................................................................................................................................. 7
References ............................................................................................................................................... 8

INFUSION WEB MARKETING PENETRATION TESTING PROPOSAL

3

Infusion Web marketing penetration testing proposal
Penetration testing project summary
Businesses continue to advance the implementation of technology in their premises as
a way of increasing their productivity and reliability of their businesses. However, the rate at
which threats to technology and networks is alarming, with studies indicating that the rate of...


Anonymous
Excellent resource! Really helped me get the gist of things.

Studypool
4.7
Trustpilot
4.5
Sitejabber
4.4

Similar Content

Related Tags