In dieser Art von Test zielt die Exploit-Phase oft darauf, System- oder Anwendungsschwachstellen in eine Möglichkeit zur Kommunikation mit dem internen Netzwerk zu verwandeln.
In this type of test, the exploitation phase often aims to transform a system/ application vulnerability into a means of communication with the internal network.
Die „klassische" Exploit-Phase beginnt mit einer Schwachstelle, mit der ein Rechner (Workstation oder Server) kontrolliert werden kann und endet mit einer Übernahme der Domain oder des Rechnerverbunds.
The "classic" exploitation phase starts with a vulnerability that allows a machine (workstation or server) to be controlled and ends with the takeover of the domain or machine cluster.
Lokale Exploit-Phase Wir bewerten die Berechtigungen des Servers und erkennen sensible Daten.
Local Exploitation Phase We will assess the privileges of the server and identify sensitive data.
Mailware Bedrohungen werden so bereits in der Exploit-Phase erkannt.
Der Shell-Code wird während der Exploit-Phase in seine endgültige Form aufgeschlüsselt.
The shell code is decrypted into its final stage during the exploitation phase.
Wir überprüfen dabei auch, ob die Authentifizierungsmechanismen umgangen werden können und ob die Sessiondaten einzelner Benutzer voneinander isoliert sind. Exploit-Phase
We will also verify if it is possible or not for the authentication mechanisms to be bypassed, and if the session data of each user are isolated or not.
Dieses „Absuchen" ist ein weiterer Teil der Exploit-Phase, in der simuliert wird, wie ein Hacker vorgehen würde, sobald er sich im internen Netzwerk befindet - beispielsweise über den kompromittierten Webserver zur Datenbank, und dann zum Hauptverzeichnis des Unternehmens zu gelangen.
"Lateral movement" is another part of the exploitation phase that aims to simulate what an attacker would do once on the internal network, such as moving from the compromised web server to the database and then to the company's main directory. Penetration Tests - Application