"Network security and penetration tests" class notes --- 01

Network security jobs related to: pull hook net
- - - 2019/4/8 - 2019/4/12
01 Penetration Testing
definition:

	安全的利用漏洞而不影响现有网络或业务的过程,其目标是为了找出企业网络(信息系统)中存在的风险,
	从而为下一步安全加固做好准备。

insufficient:

	主要利用已知的或公开的漏洞进行测试,对未知的漏洞(未公开的漏洞)不能及时发现。

02 vulnerability scan
definition:

	漏洞扫描是指基于漏洞数据库,通过扫描等手段对指定的远程或者本地计算机系统的安全脆弱性进行检测,
	发现可利用漏洞的一种安全检测(渗透攻击)行为。

insufficient:

	只识别潜在的漏洞,误报较多。

03 red team training
Definition:

	是一种评价组织的有效防御网络威胁并且提高其安全性的过程

insufficient:

	时间的限制,预设的场景方案。

Test platform
Kali linux

Kali linux是一个渗透测试安全审计平台,集成了多款漏洞检测、安全扫描、漏洞利用等安全工具。
基于Linux操作系统Debian,前身为Back Track(回溯)BT5

Kali linux installation
Here Insert Picture Description Here Insert Picture DescriptionHere Insert Picture Description
Here Insert Picture DescriptionHere Insert Picture DescriptionHere Insert Picture DescriptionHere Insert Picture DescriptionHere Insert Picture DescriptionHere Insert Picture DescriptionHere Insert Picture DescriptionHere Insert Picture DescriptionHere Insert Picture DescriptionHere Insert Picture DescriptionHere Insert Picture Description
option to download the image file
Here Insert Picture Description
selected graphical installation
Here Insert Picture Description
Here Insert Picture DescriptionHere Insert Picture DescriptionHere Insert Picture DescriptionHere Insert Picture DescriptionHere Insert Picture DescriptionHere Insert Picture DescriptionHere Insert Picture DescriptionHere Insert Picture DescriptionHere Insert Picture DescriptionHere Insert Picture Descriptionif your virtual machine has network, you can choose to use a network mirror.
Here Insert Picture DescriptionHere Insert Picture DescriptionHere Insert Picture DescriptionHere Insert Picture DescriptionHere Insert Picture DescriptionHere Insert Picture DescriptionHere Insert Picture Description

Guess you like

Origin blog.csdn.net/zhaotiannuo_1998/article/details/89226079