|
What is an External Penetration Test
This test focuses on
- server penetration testing
- router penetration testing
- firewall penetration testing
- operating system installation and maintenance.
The penetration test may be performed with non or full disclosure of the environment in question.
The engagement would start with publicly accessible information about the client, followed by network enumeration.
Network enumeration allows?suntel to target hosts, and specific network security attacks.suntel would then assess the open ports, services and specific security vulnerabilities, and use that information to gain a toehold into the environment. After a toehold is established, escalation of privilege occurs until the external environment is controlled.
What do you get at the end of the engagement
Depending on the scope of work, a typical report would include any or all of these components (reference: OSSTMM):
Network Security
- Network Surveying
- Port Scanning
- System Identification
- Services Identification
- Vulnerability Research & Verification
- Application Testing & Code Review
- Router Testing
- Firewall Testing
- Intrusion Detection System Testing
- Trusted Systems Testing
- Password Cracking
- Denial of Service Testing
- Containment Measures Testing
Social Engineering
- Request Testing
- Guided Suggestion Testing
- Trust Testing
|
Wireless Security
- Wireless Networks Testing
- Cordless Communications Testing
- Privacy Review
- Infrared Systems Testing
Communications Security
- PBX Testing
- Voicemail Testing
- FAX review
- Modem Testing
Physical Security
- Access Controls Testing
- Perimeter Review
- Monitoring Review
- Alarm Response Testing
- Location Review
- Environment Review
|
Why Suntel
- The discovery of real risks and solutions independent of any vendor
- Skills transfer for your staff as suntel will divulge all intellectual property and tools when suntel operates with you.
- A worldwide operation, so regardless of the size or location of your network, Imrposes will service your need.
- A flexible company that will work within your operational parameters.
At Suntel, an external network security attack is the most common request from our clients. Every day of the week we are performing these engagements and as such, our skill set is efficient and effective. As we are performing penetration tests on a daily basis, we are the industry experts.
We are so confident with the service we offer, we guarantee our work to our client's level of satisfaction and keep continual contact at their requests. Our clients continue to use us because we are trustworthy, knowledgeable and exceptional value.
Suntel will analyze the critical components of a Web-based portal, e-commerce application, or Web platform.
Using manual techniques and hundreds of appropriate tools the assessment pinpoints specific vulnerabilities and identifies underlying problems. The analysis integrates detailed vulnerability and countermeasure information for:
- authentication
- authorization
- session management
- data integrity
- data confidentiality
- privacy concerns
Suntel provides comprehensive reviews for:
- Fundamental Design Security
- HTML Source Management
- General Input Validation
- SQL Injection
- Cross Site Scripting
- Token Analysis (Cookies, Custom Session IDs, etc.)
- Session Security (Authentication and Authorization) .
Proactive Penetration Testing

An attacker will visit a site on a periodic basis, see if there is a new way to break into your system. If they find a way, they will leave a way to get in at a later date. The end result, you will be attacked and the ferocity is only limited by the skill of the attacker.
Current security providers will traditionally perform an assessment for a given period of time (two weeks) once a year. The problem is that you are safe for that two week period, and then left unprotected for the remaining 50 weeks.
What should you do
Continually assess your system.Suntel performs this service every business day, year round - and the investment is only one day per month. This includes automated tools, and an open minded manual assessment of your systems. At the end of the month, you will receive a report which specifies our tests, the results and recommendations. If there is an urgent issue, this is raised immediately.
Why Suntel is leading the field in making you safe
- Every business day we are looking at your systems - making sure that you are safe from new attacks.
- You receive protection every business day, investment is only one day.
- You get your own security team, investment is only one day.
- Your security team has all tools, techniques and is not included in your headcount
|