What is a Penetration Test?
Nowadays, IT systems are an integral part of our lives. Often networked, they are subject to constant threats from criminals. Malicious hackers attempt to exploit vulnerabilities in programs and servers to profit from them.
To counter such attacks, countermeasures must be taken at different levels. For example, errors can be avoided by well-trained developers or early consideration of IT security in the planning process of projects. Due to the high complexity of IT and software systems, a penetration test is especially effective means of taking preventive protection measures against hacker attacks. A penetration test is a comprehensive examination by IT security experts to determine the susceptibility of systems to attacks using the tools and methods of malicious hackers (so-called Black Hat Hackers).
IT Security through Pentests
The goal of a pentest is the security audit of a system, uncovering vulnerabilities and providing an assessment of the threat situation. In ethical hacking, the subject is manually examined and attacked by security experts as if a cracker were at work. All tests performed are documented, solutions for vulnerabilities are developed, and the results are presented to the client in a report. The client works closely with the penetration testers to achieve the desired IT security level according to urgency and importance.
What is NOT a Pentest?
Unlike penetration tests, vulnerability or security scans are automated tests, mostly for standard software and known vulnerabilities. These scans test known systems for known problems. When used for individual systems, they usually fail or do not provide relevant results. This is where the strength of penetration tests lies: after thorough preparation, the pentester carries out individual attacks tailored to the target system using various tools to simulate the numerous attack methods of hackers.
On 01.08.2016 in the category Penetration Testing published.

