Hi, excuse the noob question. I am looking for tools to get a first security assessment on a small company internal network. There are
-
Win7 and Win10 workplace machines
-
Ubuntu file servers and workplace machines
-
Qnap NAS
-
rack servers with VMWare ESXi and VSphere and a bunch of virtual Win7, Win10, Ubuntu machines
-
telephone system
-
WLAN internal network for peoples' laptops and guest access
-
a couple of switches
-
several internet routers with connections to several providers (DSL)
-
dedicated firewalls (Draytek)
-
proprietary Win based software for a few business processes (email archival, document management, accounting, etc) that are technically servers in the intranet with clients spread across the company
-
access from the outside through selected open ports, but no customer logins nor website access from the outside
-
some company data are highly sensitive
It's a takeover situation. There will be some external consultants for the detailed integration, but I''d like a quick overview to see whether there are any dead bodies buried here that need immediate attention. My background is Unix/Linux.
I'd appreciate any hints on what pieces of the network may generally be considered dangerous or which vulnerability scanners are recommended to get an assessment. Don't forget probing the firewalls from the outside.
Thanks in advance for your comments.
[link] [comments]
from hacking: security in practice https://ift.tt/3wvHsLP
Comments
Post a Comment