Security Basics mailing list archives

Re: NASA Security Audit


From: Eric <eric () sandpile net>
Date: Wed, 08 Oct 2003 21:57:21 -0500

/Black box vs. crystal box./ In a "black box" test, the intrusion testers approach the test as an outsider, with no insider knowledge of the target environment. They will be running scanners and trying to see what is "visible". This is comparable to an attack from an anonymous (usually external) hacker.

In a "crystal box" test, the intrusion testers KNOW what they are attacking and what they expect to find. They may even be provided with many, if not all of the network diagrams and names, IP addresses, platforms, services and critical data for each and every device on the network. This is akin to a "disgruntled network engineer" attack, where they do not really have much access to the systems on the network, but where they KNOW what the systems are, where they're located, what they do and possibly even how they are configured.

As for your setup. It seems reasonable enough. I think they might appreciate the FTP access through the firewall though. :-)

Eric Hagen



---------------------------------------------------------------------------
----------------------------------------------------------------------------


Current thread: