White hat hackers divide manual penetration tests into the following categories:
Comprehensive Tests – This kind of test covers an entire network. A
comprehensive test aims to determine the connections between the parts of a target.
However, comprehensive tests are time-consuming and situational.
Focused Tests – Tests that belong to this category concentrate on a specific risk or
vulnerability. Here, the hacker will use his skills in pinpointing and exploiting
certain vulnerabilities in a network.
Automated Penetration Tests
Automated tests are easy, fast, reliable and efficient. You can get detailed reports just by
pressing a single button. The program will take care of everything on your behalf. In
general, the programs used in this test are newbie-friendly. They don’t require special
skills or knowledge. If you can read and use a mouse, you’re good to go.
The most popular programs for automated tests are Metasploit, Nessus, and OpenVAs.
Metasploit is a hacking framework that can launch attacks against any operating system.
Hackers consider Metasploit as their primary weapon.
Infrastructure Tests
A computer system or network usually consists of multiple devices. Most of these devices
play an important role in keeping the system/network stable and effective. If one of these
devices malfunctions, the entire system or network might suffer. That is the reason why
penetration testers must attack the infrastructure of their targets.
The Basics of Infrastructure Tests
An infrastructure test involves internal computer networks, internet connection, external
devices, and virtualization technology. Let’s discuss these in detail:
Internal Infrastructure Tests - Hackers can take advantage of flaws in the internal
security of a network. By testing the internal structure of a target, you will be able
to identify and solve existing weaknesses. You will also prevent the members of the
organization from attacking the structure from the inside.
External Infrastructure Tests – These tests simulate black hat attacks. Because
malicious hackers will attack a network from outside, it’s important to check
whether the external defense mechanisms of that network are strong.
Comprehensive Tests – This kind of test covers an entire network. A
comprehensive test aims to determine the connections between the parts of a target.
However, comprehensive tests are time-consuming and situational.
Focused Tests – Tests that belong to this category concentrate on a specific risk or
vulnerability. Here, the hacker will use his skills in pinpointing and exploiting
certain vulnerabilities in a network.
Automated Penetration Tests
Automated tests are easy, fast, reliable and efficient. You can get detailed reports just by
pressing a single button. The program will take care of everything on your behalf. In
general, the programs used in this test are newbie-friendly. They don’t require special
skills or knowledge. If you can read and use a mouse, you’re good to go.
The most popular programs for automated tests are Metasploit, Nessus, and OpenVAs.
Metasploit is a hacking framework that can launch attacks against any operating system.
Hackers consider Metasploit as their primary weapon.
Infrastructure Tests
A computer system or network usually consists of multiple devices. Most of these devices
play an important role in keeping the system/network stable and effective. If one of these
devices malfunctions, the entire system or network might suffer. That is the reason why
penetration testers must attack the infrastructure of their targets.
The Basics of Infrastructure Tests
An infrastructure test involves internal computer networks, internet connection, external
devices, and virtualization technology. Let’s discuss these in detail:
Internal Infrastructure Tests - Hackers can take advantage of flaws in the internal
security of a network. By testing the internal structure of a target, you will be able
to identify and solve existing weaknesses. You will also prevent the members of the
organization from attacking the structure from the inside.
External Infrastructure Tests – These tests simulate black hat attacks. Because
malicious hackers will attack a network from outside, it’s important to check
whether the external defense mechanisms of that network are strong.
