スキップしてコンテンツを表示

How is Cloud Web Application Penetration Test Different from Conventional testing

0

As above topic?

For normal web application testing we are only given a URL and normal web user account. What other things can we exploit from a cloud based url? For example? Misconfigured S3 Bucket I only have come across the following so far: https://github.com/VirtueSecurity/aws-extender When I run this do I need to have other parameter in place?

2ndly, is it necessary to do a ScoutSuite on a top of a typical testing: https://github.com/nccgroup/ScoutSuite

Lastly, give a URL how to get the s3:// details?

1回答
0

For a standard penetration test where the tester is given a user login and the public URL of the web app, it does not matter where/how that app is hosted. The actions required to mitigate/remediate any findings might be different for an app running on AWS, but the test process itself should be the same.

For assessing the security of your AWS account more generally, there are a number of tools available:

For further assistance you might also consider engaging with a AWS Security Competency Partner - these partners are vetted by AWS and have a proven track-record of helping customers improve their cloud security posture.

AWS
回答済み 4年前

ログインしていません。 ログイン 回答を投稿する。

優れた回答とは、質問に明確に答え、建設的なフィードバックを提供し、質問者の専門分野におけるスキルの向上を促すものです。

関連するコンテンツ