Evaluation of penetration tests in popular operating systems and web applications
Is this your thesis?
This record came from a bulk archive import. If it’s yours, link it to your profile.
Abstract (EN)
Recently, the use of information technologies has become widespread and importance of cyber security has increased in our country and as well as in the world. Information technologies offer a complex structure of software that provides the user with various benefits and because of this structure cause security vulnerabilities. This situation makes the various institutions and organizations, individual users, corporate websites and systems vulnerable to attacks by malicious people (hacker). Information security includes all studies to prevent these attacks and secure the information stored in digital environment. Penetration testing is one of these studies. Penetration tests are carried out by experts to identify the information system deficits that are identified before malicious persons and to prepare a report on taking necessary precautions and inform the relevant persons. Particularly in our country penetration testing experts are very few and in this field there are not enough resources for those who want to develop themselves. Enterprise companies perform penetration tests in a confidential way for security purposes and only by companies employing penetration testing specialists. This situation does not allow researchers who want to study this subject and to do research and study in a real environment. In this study, a simple virtual laboratory environment based on the Domain Controller, which resembles the IT system of an enterprise, was designed. In this virtual laboratory, there are operating systems and servers such as Windows XP, Windows 7, Windows 10, Kali Linux, IIS Server, MSSQL Sever connected to Domain Controller. We have also dealt with a vulnerable website and three Android Emulator based on Kali Linux 2019. Windows XP, Windows 7, Windows 10, Linux and Android architectures were introduced and security mechanisms of these operating systems were exemined in order to understand Penetration tests and take nessesary security measures. The aim of this study is to contribute to the sector employees and researchers who want to do research on this subject in accordance with the nature of being a resource. It is aimed to examine the penetration test phases of an enterprise firm as a whole and to present to stages of identifying security vulnerabilities and exploitations practically. Keywords: Information Security, Penetration (Infiltration) Testing, Attack Methods, Cyber Security, Vulnerability Analysis.
Author
Hande Çavşi
Institution
How to Cite
Hande Çavşi (Master Thesis). Evaluation of penetration tests in popular operating systems and web applications, 2019, Kütahya Dumlupınar University.
License
Tüm Hakları Saklıdır
This work is shared under the specified license terms.
More theses from Kütahya Dumlupınar University
- Comparision of the leg and ARM CYCLE ergometer exercises in terms of the effects on physical and psychological functions in patients with undergoing coronary arter bypass surgery(2016)
- The production and characterization of zirconia-zirconium diboride (ZrO2-ZrB2) composites for structural applications(2016)
- The reflections of government grants on renewable energy sector in Turkey(2016)
- The analysis of regulation and supervision agencies' budget structures in Turkey: Banking Regulation and Supervision Agency sample (2005 - 2014 Period)(2016)
- Choised based conjoint analysis and an application(2016)
- Development of sepiolite doped materials in cement mortar adhesive(2016)