NetSPI
Virtual Application Penetration Testing Overview
Pages
3
Time to read
4 mins
Publication
Language
English
Pages
3
Time to read
4 mins
Publication
Language
English
This document is a guide on virtual application penetration testing, focusing on identifying risks associated with applications published through virtualization platforms. It details the testing methodology employed by NetSPI, which includes evaluating both anonymous and authenticated access scenarios to uncover security vulnerabilities. The guide outlines key testing areas, including policy and sandbox validation, information gathering, testing and evaluation, and data exfiltration channels. It explains how NetSPI assesses the virtual environment's policy and sandbox restrictions, aiming to identify potential circumvention paths. The document also describes the importance of application testing, emphasizing that the virtualization layer alone does not ensure security. Furthermore, it presents a comprehensive approach that combines security expertise with automated tools to identify critical vulnerabilities, providing remediation guidance and real-time reporting of vulnerabilities as they are discovered. The guide aims to assist security and development teams in effectively addressing security challenges in virtual applications.