CMIT 321 Gaining Access Plan./ Penetration Test Proposal Deliverable 3: Gaining Access Plan
Overview
After all the necessary data has been obtained during the recon and scanning phase that data will be used to gain acc
...
CMIT 321 Gaining Access Plan./ Penetration Test Proposal Deliverable 3: Gaining Access Plan
Overview
After all the necessary data has been obtained during the recon and scanning phase that data will be used to gain access. Gaining access describes the moment where the attacker acquires entry to the OS or applications on the workstation or network. The attacker can obtain entry at the network, OS, or application level. Once access has been made into the target system, then we will attempt to increase privileges to be able to take complete and total control of the target system. During this process, transitional systems that are linked to it will also be compromised.
Vulnerable Resources
There are vulnerability resources available such as scoring systems and databases that are used to rate the vulnerabilities of information system, and to offer a combined score of the overall seriousness and threat related to the identified vulnerabilities. These resources include the National Vulnerability Database (NVD), Common Vulnerability Scoring System (CVSS), and the Common Vulnerabilities Exposure (CVE).
Common Vulnerabilities and Exposures (CVE) this is an open source dictionary of regulated identifiers for common software vulnerabilities and exposures. CVE Identifiers (CVE IDs) are given by CVE Numbering Authorities (CNAs) from across the globe, this guarantees assurance amongst parties when used to converse or share data about a single software or firmware weakness, affords a standard for tool assessment, and allows information exchange for cyber security computerization. CVE IDs also offers a standard for gauging the coverage of tools and services this allows users to establish which tools are more efficient and suitable for their organization’s needs.
[Show More]