
YuChakTinMichael‘sGIACGCFWProjectAssignment
Page 177
ScenarioThree:
Segmentsinvolved:Outsideworld,Core_Net(192.168.16.0)
Remarks:
n ThistestisdesignedtofindoutifnonlegitimateremoteclientscanaccessthenetworkviaW2K_VPN.
n AhostswithdefaultWindows2000installationandsharesopenedisdeliberatelyplacedinCore_Net(behindW2K_VPN)fortesting.
*AuditPositioning:Althoughthistestinvolvesconnectingfromthe“outside”,arrangementshouldbemadesothattheinternetconnectioncan
beperformedinhouse,probablyusingadialupISPconnection.Thisminimizesthechanceofhavingthetestbeingmonitoredbyathirdparty,
asrecommendedinthebook“HackProofingyourECommerceSite”
51
.
51
PublishedbySyngress,ISBN:192899427X, http://www.syngress.com/catalog/sg_main.cfm?pid=1216
Attacker
Target
Hosts at
192.168.16.0
W2K_VPN
Scenario Three: AttackertryingtopassthroughtheVPNservertothe
internetnetwork.
Kommentare zu diesen Handbüchern