
YuChakTinMichael‘sGIACGCFWProjectAssignment
Page 162
“NSLOOKUP canbeusedtotransferanentirezonebyusingthelscommand.
Thisisusefultoseeallthehostswithinaremotedomain.Thesyntaxforthels
commandis:
ls[ a|d|ttype]domain[>filename]”
47
ScenarioFour:
Remarks:ThistestfocusesontestingwhethertheRASServercandistinguishbetweenlegitimateandillegitimateloginrequests.
*AuditPositioning:Althoughthistestinvolvesdialingfromthe“outside”intotheRASServer,arrangementshouldbemadesothatthedialing
canbeperformedinhouse,probablyusingafreephoneline.Thisminimizesthechanceofhavingthe testbeingmonitoredbyathirdparty,as
Attacker
RASServer
ScenarioFour: AttackertryingtologinviaRAS.
Comentários a estes Manuais