The Experts below are selected from a list of 21 Experts worldwide ranked by ideXlab platform
Patrick Engebretson - One of the best experts on this subject based on the ideXlab platform.
-
Post Exploitation and Maintaining Access with Backdoors, Rootkits, and Meterpreter
The Basics of Hacking and Penetration Testing, 2013Co-Authors: Patrick EngebretsonAbstract:This chapter focuses on the importance of writing the Penetration Testing Report and includes some specific details about what needs to be included and potential pitfalls for hackers who have never written a Penetration Testing Report. The importance of presenting a quality Report to the client is emphasized. The chapter concludes with suggestions about what the readers can do to further enhance their hacking skills once they have completed the book. Specific recommendations for getting advanced training and becoming part of the security community are outlined.
-
Chapter 8 – Wrapping Up the Penetration Test
The Basics of Hacking and Penetration Testing, 2013Co-Authors: Patrick EngebretsonAbstract:This chapter focuses on the importance of writing the Penetration Testing Report and includes some specific details about what needs to be included and potential pitfalls for hackers who have never written a Penetration Testing Report. The importance of presenting a quality Report to the client is emphasized. It concludes with suggestions about what the readers can do to further enhance their hacking skills once they have completed the book. Specific recommendations for getting advanced training and becoming part of the security community are outlined.
-
Wrapping Up the Penetration Test
The Basics of Hacking and Penetration Testing, 2011Co-Authors: Patrick EngebretsonAbstract:Publisher Summary The writing of a Penetration Testing Report is one of the most critical tasks performed by an ethical hacker. Many Penetration testers often collect and neatly organize the various outputs into a single Report. They gather any pertinent information from the reconnaissance phase and include it along with the output from Nmap and Nessus. An effective Penetration Testing Report should include an executive summary, a detailed Report, and raw output. The executive summary should be a very brief overview of the major findings. This document, or subReport, should not exceed two pages in length and only include the highlights of the Penetration test. The executive summary does not provide technical details or terminology. The detailed Report includes a comprehensive list of the findings as well as the technical details. The audience for this Report includes IT managers, security experts, network administrators, and others who possess the skills and knowledge required reading and comprehending its technical nature. The final portion of the Report should be the technical details and raw output from each of the tools. In reality, not every Penetration tester will agree that this information needs to be included with the Penetration Testing Report.
Setiawan Hardy - One of the best experts on this subject based on the ideXlab platform.
-
Rancang Bangun Website Visualisasi Pengelolaan Dokumen Celah Keamanan Pada Website Di Sub Domain ITS
2017Co-Authors: Setiawan HardyAbstract:Setiap tahunnya final project dari mata kuliah Keamanan Aset Informasi melakukan Penetration Testing terhadap website subdomain ITS dan menghasilkan dokumen laporan celah keamanan. Semua dokumen laporan tersebut tersimpan secara terpisah secara soft maupun hard copy. Hal tersebut menyulitkan untuk pengelolaan dokumen dan juga memerlukan ruang penyimpanan secara fisik. Berdasarkan permasalahan tersebut diperlukan sebuah tempat pengumpulan dokumen untuk memudahkan pengelolaan secara cepat dan terpusat. Selain itu banyak website di ITS yang masih memiliki celah keamanan dan belum mendapatkan penanganan untuk mencegah peretasan terjadi. Hal itu dikarenakan ketidaktahuan akan celah keamanan yang ada pada website di ITS dan tidak adanya akses ke dokumen laporan Penetration Testing yang dilakukan pada tugas Final Project mata kuliah Keamanan Aset Informasi. Pengembangan akan dilakukan dengan menggunakan framework Laravel untuk melakukan pengembangan dan uji kelayakan website. Dalam Tugas Akhir ini akan dihasilkan website yang akan digunakan untuk mengelola dokumen laporan vulnerability dan sebagai visualisasi keamanan asset informasi website yang ada di ITS. ==================================================================== Each year the final project of the Information Asset Security course performs Penetration Testing of the ITS subdomain website and produces a security loopholes document. All Report documents are stored separately in soft or hard copy. This makes it difficult for document management and also requires physical storage space. Based on the problem, a document collection is needed to facilitate quick and centralized management. In addition, many websites in ITS that still have security holes and have not get handling to prevent hacking occurs. This is due to the ignorance of the security gaps that exist on the website at ITS and the lack of access to the document Penetration Testing Report conducted on the task of Final Project Asset Information Security course. Development will be done using the Laravel framework to develop and test the website's feasibility. In this Final Project will generate a website that will be used to manage Report documents vulnerability and as a visualization of the security of information assets website in ITS
Andrew Bindner - One of the best experts on this subject based on the ideXlab platform.
-
Reports and Templates
Hacking with Kali, 2014Co-Authors: James Broad, Andrew BindnerAbstract:This chapter describes the parts of the Penetration Testing Report and includes some information about what should be included in each section.
James Broad - One of the best experts on this subject based on the ideXlab platform.
-
Reports and Templates
Hacking with Kali, 2014Co-Authors: James Broad, Andrew BindnerAbstract:This chapter describes the parts of the Penetration Testing Report and includes some information about what should be included in each section.
Nikolaos Tsalis - One of the best experts on this subject based on the ideXlab platform.
-
Thesis scope Five major Penetration Testing methodologies: ISSAF, NIST,
2016Co-Authors: Ilias Boutsikakis, Nikolaos TsalisAbstract:Comparison analysis of methodologies on specific criteria Proposal of a unified Penetration Testing methodology Proposal of a Penetration Testing tools set Lab Setup and Results Analysis of a Penetration Testing scenario Development of a Nessus parser, written in Java, for automatic results exportation Proposal of a Penetration Testing Report template Conclusions Planning and Preparation are usually overlooked by the Penetration Testing team. Information Gathering stage is the stage that provides the next stages with information. Vulnerability Identification stage results must be verified through Validity processes