• Penetration Test


    Post-report Activities

    POST-REPORT DELIVERY ACTIVITIES
    • Delivering the report isn't the end
      • There is more work to do
      • Delivering may include presenting the report
    • Post-report delivery activities - clean up any changes you made
      • Removing all of these
        • Shells
        • Tester-created credentials
        • Tools
      • Clean up history
      • Leaving artifacts can weaken the client
    • Client acceptance
      • Formal cessation of project activities and acceptance of deliverable
      • The client formally says "You're done."
      • Client should sign a statement of acceptance
    • Lessons learned
      • Crucial step in project closure
      • Helps to continuously improve
    • Follow-up actions/retest
      • Client may need more actions based on findings
      • Be careful to avoid extending the project scope here without a change process
    • Attestation of findings
      • Independent review and assurance of findings(i.e. third party)
    QUICK REVIEW
    • Remove all test activity artifacts
    • Get formal client acceptance
    • Conduct "lessons learned" sessions with the client and capture the findings
    • Follow up on client add-on requests
    相信未来 - 该面对的绝不逃避,该执著的永不怨悔,该舍弃的不再留念,该珍惜的好好把握。
  • 相关阅读:
    SDK 和 RunTime 的区别
    P7740[NOI2021]机器人游戏【dp,bitset】
    sql注入之盲注
    linux/windows自启动和行踪清理
    口令嗅探sniffe
    一句话木马
    php执行linux命令
    windows 防火墙和UAC
    msfvenom,转
    XSS最关键的一步
  • 原文地址:https://www.cnblogs.com/keepmoving1113/p/14152072.html
Copyright © 2020-2023  润新知