Lean Security Expert Lean Security Expert

A Business Owner’s Basic Guide to Pen Testing

Pen testing, short for penetration testing, has never been more important than it is today. Here’s a basic guide for you;

Pen testing, short for penetration testing, has never been more important than it is today. With ransomware, phishing, DDoS attacks and countless other tactics used by increasingly sophisticated cybercriminals, the best defence starts with knowing your strengths and weaknesses.

What is pen testing?

Pen testing is the practice of evaluating a system’s security infrastructure to find potential vulnerabilities and understand how the system could be attacked. This information is then used to suggest countermeasures that can be taken to reduce the risk of security breaches and improve security maturity.

Pen testing is conducted by hiring cybersecurity professionals. The security professionals are authorized by the company to conduct a simulated attack on its behalf to test its computer system, network, software application or other computing resource for potential loopholes.

Since the goal of a pen test is to help the company strengthen its security infrastructure, and the findings of the test are strictly used for that purpose and that purpose only, pen testers are also commonly referred to as ethical or white hat hackers.

The pen testing process

A typical pen testing process involves five steps:

· In the first step, pen testers gather information about the computing resource that needs to be tested. This information is gathered by using different tools.

· In the second step, the gathered information is studied by the testing team to identify potential vulnerabilities in the system.

· In the third step, an attack is designed to exploit the identified vulnerabilities.

· In the fourth step, the testing team evaluates the significance of the data at risk and prioritizes the vulnerabilities accordingly.

· In the fifth and last step, pen testers report on their findings and recommend ways on how the vulnerabilities can be eliminated.

Wrapping up

Sun Tzu wrote in the Art of War: “If you’re ignorant of your enemy and yourself, you’re certain to be in peril.”

Pen testing offers intelligence on how your enemy (a potential attacker) might exploit your system resources and provides insight into your strengths and weaknesses, so that you can better prepare against future cyber attacks. 

Looking for a comprehensive pen testing service for your business?

Lean Security can help.

We are expert pen testers, headquartered in the beautiful state of New South Wales. We specialize in mobile application pen tests, web application pen tests, web service pen tests, IoT pen tests, external network pen tests and source code pen tests. Contact us today to discuss your pen testing needs.   

Read More
Network Security Lean Security Expert Network Security Lean Security Expert

Bots, Bots Everywhere: 5 Largest DDoS Attacks in the History of the Internet

We know how a DDoS attacks can overwhelm a system’s resources and take it down to the ground.  

We know how a DDoS attacks can overwhelm a system’s resources and take it down to the ground.  

But sometimes DDoS attacks can scale beyond our wildest imaginations. We’re talking about attacks that clock bandwidths in tera and giga bite ranges and notoriously leave their marks in history books.

Spamhaus

Spamhaus is a non-profit anti-spam organization based in London and Geneva.

In 2013, Spamhaus website, email servers and DNS IPs were taken down by a DDoS attack that measured in at 300 gigabits per second.

Investigations traced the attack to a member of Dutch company named Cyberbunker.

CloudFlare

CloudFlare is a content delivery network (CDN) and security service provider headquartered in San Francisco.

In 2014, CloudFlare’s network was slammed by a DDoS attack that peaked at more than 400 gigabits per second.

The attack was originally directed at a CloudFlare customer, but it was so powerful that it brought down the company’s entire network to its knees.   

The perpetrators leveraged the NTP servers to launch the attack.

Occupy Central Movement

Occupy Central was a Hong Kong civil disobedience campaign initiated by Benny Tai, Reverend Chu Yiu-ming and Dr. Chan Kin-man in 2013, advocating for a democratic electoral system.

Unimpressed by the movement, attackers sent large amount of traffic to Occupy Central’s webhosting services, causing the servers to crash.

The DDoS attack recruited five botnets and measured in at 500 gigabits per second.

2) Dyn

Dyn, Inc. is an internet performance management and web application security company based in the U.S.

In 2016, Dyn was targeted by a series of DDoS attacks which spiked up to 1.2 terabits per second.  The attacks used mirai-infected IoT-enabled devices to bombard the company’s servers.

The SpainSquad, New World Hackers and Anonymous claimed the responsibility for the attacks.

GitHub

GitHub is a code hosting platform for collaboration and version control.

On February 28, 2018, GitHub was taken down by a DDoS attack that clocked in at a whopping 1.35 terabits per second.  

Interestingly, the attack did not use any botnet network, and instead relied on misconfigured Memcached servers for amplification.   

The attack remains the largest DDoS attack ever recorded in the history of the internet. 

Is your business protected against potential DDoS attacks? Don’t be vulnerable; call our cybersecurity experts today and make sure you’re covered from any and all threats.    

Read More
Lean Security Expert Lean Security Expert

Cloud-Based Mobile Application Testing—What Should You Focus On?

Here are some important things to focus while getting your application tested through a cloud-based server.

As the mobile app industry thrives globally, Australia has also observed a stark increase in the usage of mobile applications over the past few years. The total revenue generated by Australian mobile app industry was expected to be $2 billion between the years 2018–2019. This increased demand also calls for quality and secure experience.

Understanding Mobile App Security

To measure the performance of applications, every mobile application has to pass standard tests and checks. And one of the most techniques for testing apps is cloud-based testing. Hiring a service provider for cloud-based app testing allows business owners to simulate the hardware of a device virtually. This significantly reduces the time required to check a mobile application for threats and vulnerabilities.

What Comes Next?

If you’re all set to get your application checked, you need to consider a few points beforehand. Here are some important things to focus while getting your application tested through a cloud-based server.

Know About Your Device

Testing your device on a cloud isn’t as easy as it seems. You need to learn about the type of your machine and all the other devices and technologies that are compatible with it. It might be possible that the platform of your app doesn’t support cloud computing. This can be a major problem for business owners.

development process of your mobile app.png

 

During the development process of your mobile app, prioritize all the security tests. Learn about the model of your device, system software and core information of your app to ensure compatibility with your cloud server.

Infrastructure Issues

Your services provider might not be able to provide all the relevant resources for a cloud-based mobile app testing. They might need to create the testing environment from scratch for you. This can create a huge hurdle during your procedure, wasting a lot of time and money.

 

Before selecting a security consultant, make sure they have the necessary technology, configuration, and storage space to carry out your security checks.

Cost of the Procedure

Before you start working with a company to test your business application on a virtual server, it’s better to learn about any hidden charges. Amateurs often end up using test environments incorrectly. This can result in a sudden rise in the cost of the testing procedure.

To avoid this, make sure to plan your testing procedure in detail with the vendor and consider all additional costs like data encryption and extra use of resources.

For sophisticated and trustworthy cloud-based testing, secure cloud managed hosting and mobile application penetration testing, contact Lean Security at 61 (2) 8078 6952. Our wide range of services can help you detect all sorts of software vulnerabilities.

Read More
Lean Security Expert Lean Security Expert

Web Application Security Testing: Focusing on Certain Areas of Web App

Here are some important aspects that should be considered before you perform a security test on your web application.

Nowadays, businesses are highly depended on web-based data. The Australian e-commerce market experienced a growth of 11.5% from 2016–2017 and has been following a similar trend since then. A huge amount of data is exchanged, stored and transferred through online platforms on a daily basis.

With such a rapid rate of growth, accountability and security of online assets are of utmost priority for all businesses. Therefore, companies are advised to carry out necessary tests to ensure the safety of their websites and online applications.

Stringent web security tests are imperative in the modern world. It ensures that confidential information remains safe from malicious online attacks and hackers. It makes sure that only authorized users can access sensitive data.

Here are some important aspects that should be considered before you perform a security test on your web application.

Keep Strong Login Credentials:

A user name and password of your online site plays a key role in its protection. And hackers are always finding tools to crack this information.  All they need is to guess possible keywords for your login credentials. Once they find their way in, they can access your applications inside and out.

Login Credentials.png

 

Web security testing will help you detect vulnerabilities in your application such as your password strength. Therefore, it’s always advised to keep a complex password, something that isn’t easy to guess. Weak passwords are cracked easily and hacked by cybercriminals, leaving your information vulnerable.

Regular Checks:

This is one of the most crucial steps for securing web platforms. But it’s often neglected or forgotten. Businesses that store customer information should perform routine checks. These tests will check for potential vulnerabilities and threats to your application.

This step is often considered a compulsory requirement by many government industries. It should be followed regularly during web application security testing.

Software Testing Practices:

During software development, security testing should be one of the first steps and shouldn’t be neglected at any cost. Don’t leave security tests for the end. Perform an early security test while you design the website or application for your business.

If any vulnerability is identified during the process, it can be a huge setback in the development of your application. Involve your development operation team to reduce the risk and cost of remediation.

Fixing Bugs:

During the process of security testing, the development team often finds vulnerabilities called software bugs. Rather than making a list of these issues to be solved later on in the development cycle, it’s a great approach to fix them at hand. Prioritize these fixes and avoid delays.

mobile application penetration test.png


If you’re looking for an expert opinion on the advanced web security testing and mobile application penetration test, get in touch with Lean Security. Our services will safely secure all of  your confidential data.

Read More