preview

Penetration Plan Essay

Better Essays

Running Head: E-commerce Sales

Unit 1
E-commerce Sales
Penetration Test Plan

Tom Moccia
IT542 Dr. Matthew North
Kaplan University
March 19, 2013

Table of Contents Scope 3 Goals and Objectives 4 Tasks 4 Reporting 7 Schedule 9 Unanswered Questions 10 Authorization Letter 11 References 13

Scope

This Vulnerability and Penetration Test Plan is designed specifically for E-commerce Sales and is designed to determine what steps need to be taken to secure and protect the network against malicious attacks. This Vulnerability and Penetration Test will cover numerous aspects of the E-commerce Sales information …show more content…

(Infond Securite Informatique, 2010) This information can be acquired through public record information such as accessing public whois information, accessing the American Registry of Internet Numbers and the “dig” command available on many Unix systems (Federal Office of Information Security, n.d.). This public information acquired from publically accessible registries or techniques will provide a solid base for moving forward with the probing tests. After the initial information gathering process more comprehensive tools will be implemented to evaluate security and carry out the penetration test. Some or all of the tools listed will be used in the overall test phase. Nmap: The standard of network scanning tools creates network packets to elicit responses. This tool tricks the target machine to revealing more information than a traditional ping (Northcutt, Shenk, Shackleford, Rosenberg, Siles & Mancini, 2006). Cheops-ng: A versatile tool that will scan hosts and map the network by using a client server interface to segregate users from the scanning tool. NetCraft: Tool to examine the network and determine what hosts are connected (Wirelessdefence.org, 2010). Wireshark: Allows testers to analyze network traffic in a GUI that can be used for reporting as well (Wirelessdefence.org, 2010). Strobe: This utility will scan the ports and report on which ports are

Get Access