
YuChakTinMichael‘sGIACGCFWProjectAssignment
Page 181
ScenarioFour:
Segmentsinvolved:Outsideworld,Internal_Clients(192.168.17.0), Internal_Admin(192.168.19.0), Internal_Dev(192.168.20.0)
Remarks: Thistestattemptstofindout:
n whetherthreatscanflowthroughtotheinternalnetwork
n whetherattackersarepreventedfrommakinguseoftheproxyfunction
*AuditPositioning:Althoughthistestinvolvesconnectingfromthe“outside”,arrangementshouldbemadesothattheinternetconnectioncan
beperformedinhouse,probablyusingadialupISPconnection.Thisminimizesthechanceofhavingthetestbeingmonitoredbyathirdparty,
asrecommendedinthebook“HackProofingyourECommerceSite”
53
.
53
PublishedbySyngress,ISBN:192899427X, http://www.syngress.com/catalog/sg_main.cfm?pid=1216
ScenarioFour: Attackertryingtocompromisetheproxyserver.
Attacker
Hostsat
192.168.17.0
192.168.19.0
192.168.20.0
ISA_Cache
Comentarios a estos manuales