Vulnerability Assessment & Penetration Test
Home » Cyberfero Projects » Vulnerability Assessment & Penetration Test
- ♦ identify IT security vulnerabilities in the corporate network and systems (especially systems deemed critical), including web servers;
- ♦ verify that the behavioral policies and procedures in place, and the related training, are correct and complete, so as to prevent the security risks that arise from users’ carelessness or lack of awareness when using IT systems.
OBJECTIVES
The Vulnerability Assessment (VA) / Penetration Test (PT) service lets you verify how robust your network is through the following activities:- ♦ Network sniffing.
- ♦ IP and port scanning.
- ♦ ARP spoofing.
- ♦ Access to the corporate network.
- ♦ Attempts to steal or guess domain passwords.
- ♦ Search for vulnerabilities at layers 2, 3 and 7 of the ISO/OSI stack.
- ♦ Exploitation of any vulnerabilities found to gain control of systems/services.
- ♦ Analysis, verification and interpretation of the results.
ACRONYMS AND ABBREVIATIONS
IVA = Internal Vulnerability Assessment EVA = External Vulnerability Assessment IPT = Internal Penetration Test EPT = External Penetration TestMETHODOLOGY
Our methodology measures corporate IT security through four macro steps:- 1) Internal Vulnerability Assessment (Step 1).
- 2) External Vulnerability Assessment (Step 2).
- 3) Internal Penetration Test (Step 3).
- 4) External Penetration Test (Step 4).
INTERNAL VULNERABILITY ASSESSMENT (IVA)
The robustness of the IT security measures will be verified from the inside (trusted network), by identifying which known vulnerabilities could be exploited by malicious users to carry out cyber attacks.
This involves running non-destructive “scans” of the systems, using tools designed to detect the status of standard operating systems and applications.
These are the same tools commonly used by malicious users and freely available on the Internet; on request, tools from well-known security software vendors can be used instead. Whether public open-source tools or commercial products are used makes no substantial difference to the results.
When analyzing the vulnerabilities and weaknesses of the infrastructure as a whole, the critical ones will be highlighted. A “critical” vulnerability is one that could cause serious and immediate damage, such as business disruption, loss of sensitive data, or loss of credibility, reputation or money. This allows immediate action to be taken to mitigate the problem.
At the end of the activity, the results will be summarized in a Vulnerability Assessment Report.
IVA TARGET
The Target is the set of elements covered by the Vulnerability Assessment. It varies according to the structural characteristics of the organization being analyzed and the type of VA being conducted. Based on initial considerations, the Target is the LAN (a connection to any LAN segment), regarded as a weak link in the network infrastructure. The Target may later be adjusted based on further observations and on the results of the VA. The proposed target includes the following devices within the LAN:- ◊ Network devices.
- ◊ Security devices.
- ◊ Application servers.
- ◊ Storage servers.
IVA PHASES
The project is divided into the following phases:- 1) Reconnaissance.
- ◊ Network structure (reverse engineering to map the network topology).
- ◊ Identification and classification of servers and network devices that are “critical” from a security architecture standpoint.
- ◊ Identification of the operating systems in use (OS fingerprinting).
- ◊ Research of public information on the applications in use.
- 2) Vulnerability Assessment.
- 3) Vulnerability classification.
- 4) Reporting and countermeasure management.
IVA REPORT
The Internal Vulnerability Assessment report comprises all the documentation delivered at the end of the activity. Figure 2 outlines the first step described above, highlighting the reporting phase as the output of the IVA activity. The report will contain the following information:- ♦ List of vulnerabilities, if any, for each server / network device.
- ♦ Vulnerability classification.
- ◊ High (Critical): vulnerabilities that pose, or may pose, a serious risk to the company.
- ◊ Medium: medium-risk vulnerabilities, exploitable through few attack vectors or with limited impact on the company.
- ◊ Low: vulnerabilities with little or no impact on business productivity.
- ♦ Best practices.
EXTERNAL VULNERABILITY ASSESSMENT (EVA)
EVA TARGET
Based on initial considerations, the Target is the set of perimeter network devices that physically separate the LAN from the Internet (the trusted and untrusted networks). The Target may later be adjusted based on further observations and on the results of the VA. The proposed target includes the following network devices:- ♦ Security devices.
- ◊ Firewalls.
- ◊ VPN terminators.
- ◊ Access points / radio bridges.
- ♦ Application servers.
EVA PHASES
The project is divided into the following phases:- 1) Reconnaissance.
- ♦ Perimeter network structure (reverse engineering to map the network topology).
- ♦ Identification and classification of servers and network devices that are “critical” from a security architecture standpoint.
- ♦ Identification of the operating systems in use (OS fingerprinting).
- ♦ Identification of remote access methods.
- ♦ Research of public information on the company requesting the security test.
- ♦ Research of public information on the applications in use.
- 2) Vulnerability Assessment.
- 3) Vulnerability classification.
- 4) Reporting and countermeasure management.
EVA REPORT
The External Vulnerability Assessment report comprises all the documentation delivered at the end of the activity. Figure 3 outlines the second step described above, highlighting the reporting phase as the output of the EVA activity. The report will contain the following information:- ♦ List of vulnerabilities, if any, for each server / network device.
- ♦ Vulnerability classification.
- ♦ High (Critical): vulnerabilities that pose, or may pose, a serious risk to the company.
- ♦ Medium: medium-risk vulnerabilities, exploitable through few attack vectors or with limited impact on the company.
- ♦ Low: vulnerabilities with little or no impact on business productivity.
- ♦ Best practices.
INTERNAL PENETRATION TEST (IPT)
IPT TARGET
Based on initial considerations, the Target is the LAN (a connection to any LAN segment), regarded as a weak link in the network infrastructure. The Target may later be adjusted based on further observations and on the results of the VA. The proposed target includes the following devices within the LAN:- Network devices.
- Security devices.
- Application servers.
- Storage servers.
IPT PHASES
- Application server exploitation.
- Network penetration.
- Privilege escalation.
- Reporting and countermeasure management.
IPT REPORT
The Internal Penetration Test report comprises all the documentation delivered at the end of the activity. Figure 4 outlines the third step described above, highlighting the reporting phase as the output of the IPT. The report will contain the following information:- Attack methods (exploits) used.
- Best practices.
EXTERNAL PENETRATION TEST (EPT)
EPT TARGET
Based on initial considerations, the Target is the set of perimeter network devices that physically separate the LAN from the Internet (the trusted and untrusted networks). The Target may later be adjusted based on further observations and on the results of the VA. The proposed target includes the following network devices:- Security devices.
- Firewalls.
- VPN terminators.
- Access points / radio bridges.
- Application servers.
EPT PHASES
- Application server exploitation.
- Network penetration.
- Privilege escalation.
- Reporting and countermeasure management.
EPT REPORT
The External Penetration Test report comprises all the documentation delivered at the end of the activity. The report will contain the following information:- Attack methods (exploits) used.
- Best practices.
Customers
Twitter FEED
Recent activity
-
SecureOnlineDesktop
Estimated reading time: 6 minutes L'impatto crescente delle minacce informatiche, su sistemi operativi privati op… https://t.co/FimxTS4o9G
-
SecureOnlineDesktop
Estimated reading time: 6 minutes The growing impact of cyber threats, on private or corporate operating systems… https://t.co/y6G6RYA9n1
-
SecureOnlineDesktop
Tempo di lettura stimato: 6 minuti Today we are talking about the CTI update of our services. Data security is… https://t.co/YAZkn7iFqa
-
SecureOnlineDesktop
Estimated reading time: 6 minutes Il tema della sicurezza delle informazioni è di grande attualità in questo peri… https://t.co/tfve5Kzr09
-
SecureOnlineDesktop
Estimated reading time: 6 minutes The issue of information security is very topical in this historical period ch… https://t.co/TP8gvdRcrF
Newsletter
Products and Solutions
News
- From Cyberfero to Cyberfero: rebranding of the leading cybersecurity company May 6, 2024
- NIS: what it is and how it protects cybersecurity April 22, 2024
- Advanced persistent threats (APTs): what they are and how to defend yourself April 17, 2024
- Penetration Testing and MFA: A Dual Strategy to Maximize Security April 15, 2024
- Penetration Testing: Where to Strike to Protect Your IT Network March 25, 2024
Google Reviews

Davvero consigliata !!!!!
In particolare vorrei sottolineare la figura che piu’ racchiude e sintetizza le qualità della Secure Online Desktop , il suo AD Ing. Piergiorgio Venuti, professionista impagabile , sia dal punto di vista tecnico/organizzativo che soprattutto (e non dimeno) come persona , capace di gestire , risolvere e approcciare qualsivoglia attività/problematica, davvero un grande !!!!







Tempi veloci e staff preparato!
Ottima azienda, servizi molto utili, staff qualificato e competente. Raccomandata!read more
Ottimo supportoread more
E' un piacere poter collaborare con realtà di questo tiporead more
Un ottimo fornitore.
Io personalmente ho parlato con l' Ing. Venuti, valore aggiunto indubbiamente.read more
© 2024 Cyberfero s.r.l. All Rights Reserved. Sede Legale: via Statuto 3 - 42121 Reggio Emilia (RE) – PEC [email protected] Cod. fiscale e P.IVA 03058120357 – R.E.A. 356650 Informativa Privacy - Certificazioni ISO



