Home > Security Channel Project Guides > Network Penetration Testing Services > Pen Testing Methodology > Storage penetration testing
Project Guides: Network Penetration Testing Services:
EMAIL THIS
 START   INTRODUCTION   SELLING NETWORK PEN TESTING SERVICES   METHODOLOGY   TOOLS   
Pen Testing Methodology

<< PREVIOUS | NEXT >>: Penetration testing -- Securing wireless access...
 TIPS & NEWSLETTERS TOPICS 

PLATFORM SECURITY

Storage penetration testing


Kevin Beaver
04.06.2007
Rating: --- (out of 5)


Digg This!    StumbleUpon Toolbar StumbleUpon    Bookmark with Delicious Del.icio.us   


This tip will teach value-added resellers (VARs), systems integrators and security consultants determine which security tests to perform, and which tools to use to ethically hack a customer's storage systems and uncover hidden vulnerabilities.

Hack your storage to test your security
It used to be that storage systems existed on small, trusted networks with minimal access. Now, with the never-ending expansion of storage systems, multiple administrators, management software "feature bloat" and the co-mingling of non-sensitive and sensitive information on the same storage systems, storage systems have taken on complexities of their own and are proving to be more and more vulnerable to security breaches.

When it comes to testing for vulnerabilities in storage systems (DAS, NAS, and SANs), it's easy to overlook weaknesses that may be obvious to a malicious insider or other attacker. From perimeter security weaknesses to insider advantages, such as knowing just where sensitive storage devices are located, these kinds of hit-or-miss issues will get you every time.

Learn more best practices for storage penetration testing so that you can keep your customers' storage safe from attacks.

About the author
Kevin Beaver is an independent information security consultant, author and speaker with Atlanta-based Principle Logic LLC. He has more than 17 years of experience in IT and specializes in performing information security assessments. Beaver has written five books, including
Hacking For Dummies (John Wiley & Sons, Inc.), the brand new Hacking Wireless Networks For Dummies and The Practical Guide to HIPAA Privacy and Security Compliance (Auerbach Publications). He can be reached at kbeaver@principlelogic.com.


Rate this Tip
To rate tips, you must be a member of SearchSecurityChannel.com.
Register now to start rating these tips. Log in if you are already a member.




Digg This!    StumbleUpon Toolbar StumbleUpon    Bookmark with Delicious Del.icio.us   


<< PREVIOUS | NEXT >>: Penetration testing -- Securing wireless access...
VIEW ALL IN THIS CATEGORY


RELATED CONTENT
Pen Testing Methodology
Penetration testing 101: How to offer pen test services
Penetration testing reconnaissance -- Footprinting, scanning and enumerating
Penetration testing -- Big bad bugs
Penetration testing -- Social engineering, IDS and honey pots
Penetration testing -- Securing wireless access points
Cross-site scripting vulnerability penetration testing
VPN penetration testing
Secure the domain controller with a penetration test
When should automated penetration testing be supplemented with manual pen testing?
Web application penetration testing: Best practices

Penetration Testing and Ethical Hacking
Security site assessment FAQ: Podcast with Joel Scambray
Penetration testing 101: How to offer pen test services
How to prepare for network penetration testing services
Network penetration tools
Top five security service provider tips of 2007
Checklist: Top five security assessment tools
Penetration testing tutorial for service providers
An introduction to penetration testing and its legal implications for VARs and consultants
Penetration testing reconnaissance -- Footprinting, scanning and enumerating
Network penetration testing: Ethical hacking tools and techniques

Pen Testing Tools
Penetration testing 101: How to offer pen test services
Penetration testing reconnaissance -- Footprinting, scanning and enumerating
Network penetration testing: Ethical hacking tools and techniques
Penetration testing -- Social engineering, IDS and honey pots
Nmap Tutorial: An introduction for VARs and security consultants
Metasploit -- A penetration testing must-have
Nessus Tutorial: Using the open source vulnerability scanning tool
VPN penetration testing
A review of Skybox Security's Skybox View 3.0
A review of Cenzic's Hailstorm v2.6

RELATED RESOURCES
2020software.com, trial software downloads for accounting software, ERP software, CRM software and business software systems
Search Bitpipe.com for the latest white papers and business webcasts
Whatis.com, the online computer dictionary

DISCLAIMER: Our Tips Exchange is a forum for you to share technical advice and expertise with your peers and to learn from other enterprise IT professionals. TechTarget provides the infrastructure to facilitate this sharing of information. However, we cannot guarantee the accuracy or validity of the material submitted. You agree that your use of the Ask The Expert services and your reliance on any questions, answers, information or other materials received through this Web site is at your own risk.

HomeNewsTopicsITKnowledge ExchangeTipsMultimediaWhite PapersBlogsEvents
About Us  |  Contact Us  |  For Advertisers  |  For Business Partners  |  Site Index  |  RSS
SEARCH 
TechTarget provides technology professionals with the information they need to perform their jobs - from developing strategy, to making cost-effective purchase decisions and managing their organizations' technology projects - with its network of technology-specific websites, events and online magazines.

TechTarget Corporate Web Site  |  Media Kits  |  Site Map




All Rights Reserved, Copyright 2006 - 2009, TechTarget | Read our Privacy Policy
  TechTarget - The IT Media ROI Experts