| About | Products | News | Press | Resources | Awards | Jobs | Contact

SecPoint® - anti-spam appliance, web filter, vulnerability scanning, wifi security

What is a Security Exploit?

 

When an attacker identifies a security vulnerability in a software application, for example a mail server, a web server, a DNS server, a ftp server or a firewall system or other devices the goal will be to gain leveraged access on the target system.

There are many types of security vulnerabilities. The most common are buffer overflow and stack overflow. Generally overflow vulnerabilities causes the software application to do something that it is not meant to. In order to exploit these vulnerabilities to gain leveraged privileges on the target system, an attacker is required to write a piece of source code called “an exploit”. This will take advantage of the identified security vulnerability and push the software to the limit, breaking it and in the breaking process gaining leveraged access to the target system with the same privileges as the given program that is being attacked.

 

What is the difference by launching a real attack and doing a vulnerability scan?

 

Doing a Vulnerability Scan it is harmless process that uses many techniques to identify vulnerable applications on the target system. This could be by relying on version banners from the software, look the presence of the vulnerable files, and identify old non patched software and many more techniques.

 

However when relying on version banners, presence of known vulnerabilities and other techniques you can not always be 100% certain that a vulnerability is found since that you did not do the physical break in and get the leveraged privileges.

 

Why is it important to be able to launch a real exploit?

 

It is important to launch a real exploit against your system in order to determine as close as possible to 100% that all your patches are working and that you are running the latest versions and service packs on your system. What are the risks of launching a real exploit?

 

Doing a vulnerability scan which rely on version banners, presence of known vulnerable files and / or other techniques, is a very smooth process that is designed not to harm anything on your system and not to be aggressive at all.

 

When launching a real exploit even though The SecPoint Exploitation framework has been designed to minimize risks, there will always be a risk of crashing the target application.

 

It is therefore highly recommend to test all your pre-production systems by launching real exploits at them, so when they go online in a production environment you are ensured the high security of the systems. However it is obviously still necessary to test your production systems as new threats occurs on a daily basis.

SecPoint® - What is a Real Exploit? - Appliance vs Software
SecPoint® - What is a Real Exploit? - What is Cross Site Scripting(XSS)?
SecPoint® - What is a Real Exploit? - What is SQL Injection?
SecPoint® - What is a Real Exploit? - What is a Routing Table?
SecPoint® - What is a Real Exploit? - What is High Availability?
SecPoint® - What is a Real Exploit? - What is Grey Listing?
SecPoint® - What is a Real Exploit? - What is a Web Filter?
SecPoint® - What is a Real Exploit? - What is a Vulnerability?
SecPoint® - What is a Real Exploit? - What is a Proxy Server?
SecPoint® - What is a Real Exploit? - What is a Firewall?
SecPoint® - What is a Real Exploit? - What is a Cookie?
SecPoint® - What is a Real Exploit? - What is a Bayesian Filter?
SecPoint® - What is a Real Exploit? - Test Your Security Policy
SecPoint® - What is a Real Exploit? - Email & Spam Test Links
SecPoint® - What is a Real Exploit? - What is RoHS Weee?
SecPoint® - What is a Real Exploit? - What is Vulnerability Scanning?
SecPoint® - What is a Real Exploit? - What is Vulnerability Assessment?
SecPoint® - What is a Real Exploit? - What is Penetration Testing?
SecPoint® - What is a Real Exploit? - What is a Security Exploit?
SecPoint® - What is a Real Exploit? - What is Appliance Scanning?
SecPoint® - What is a Real Exploit? - What is Zero Day?
SecPoint® - What is a Real Exploit? - What is Unified Threat Management?
SecPoint® - What is a Real Exploit? - What is Intrusion Prevention?
SecPoint® - What is a Real Exploit? - What is a Content-Filter?
SecPoint® - What is a Real Exploit? - What is VoIP
SecPoint® - What is a Real Exploit? - What is Virus?
SecPoint® - What is a Real Exploit? - What is Spyware?
SecPoint® - What is a Real Exploit? - What is Phishing?
SecPoint® - What is a Real Exploit? - What is P2P?
SecPoint® - What is a Real Exploit? - What is Instant Messaging?
SecPoint® - What is a Real Exploit? - What is Spam?
SecPoint® - What is a Real Exploit? - White Papers
SecPoint® - What is a Real Exploit? - Technology Papers

© Copyright 1999-2008: SecPoint®
SecPoint ApS - Lergravsvej 53 - 2300 Copenhagen S - Phone +45 70 235 245
Privacy Statement | Link Policy | User Policy | SecPoint® Blog | SecPoint® Picture Archive |

Anti-Spam Appliance - Anti-Spam Firewall - Unified Threat Management Appliance
Anti-Virus - Web Filter Appliance - Anti Spam Appliance - Anti Spam Firewall - UTM Appliance

Wifi Security - Wifi Pen Test - Wifi Crack - Wifi Hack - Wifi Audit - Wep Wpa2 Crack

Vulnerability Scanner - Vulnerability Assessment - Security Scanner - Pen Test Appliance