Book Image

Mastering Metasploit

By : Nipun Jaswal
Book Image

Mastering Metasploit

By: Nipun Jaswal

Overview of this book

Table of Contents (17 chapters)
Mastering Metasploit
Credits
About the Author
About the Reviewers
www.PacktPub.com
Preface
Index

Performing a white box penetration test


White box testing is a testing procedure where the attacker has complete knowledge of the system he or she is going to test. This information includes operating system (OS) details, web application deployed, the type and version of servers running, and every other technological detail required to complete the penetration test.

White box testing may include visiting the client's office, talking to the end users, reviewing the source code, and so on.

The marginal difference between the black box and white box testing technique is that the tester does not have to worry about false positives with white box testing, as they already know the details of the particular application that is running. However, false positives are the wrong assumptions about a target vulnerability that may not exist in reality. Hence, a greater success is achieved from performing a penetration test using the white box testing technique than the black box testing technique.

Tip

White...