Black box penetration testing vs white box penetration testing

imagensecforcepost.png

One of the common questions that we get from our clients is about the differences between a black box penetration test and a white box penetration test.

White box testing, also known as clear box testing or glass box testing, is a penetration testing approach that uses the knowledge of the internals of the target system to elaborate the test cases. In application penetration tests the source code of the application is usually provided along with design information, interviews with developers/analysts, etc. In infrastructure penetration tests network maps, infrastructure details, etc. are provided. The goal of a white box penetration test is to provide as much information as possible to the penetration tester so that he/she can gain insight understanding of the system and elaborate the test based on it.

White box penetration testing has some clear benefits:

However, there are also some disadvantages:

A black box penetration test requires no previous information and usually takes the approach of an uninformed attacker. In a black box penetration test the penetration tester has no previous information about the target system.

The benefits of this type of attack are:

The disadvantages of a black box penetration test are:

When commissioning a penetration test, there is no right/wrong decision about white box or black box, it really depends on the scenario that needs to be tested.

You may also be interested in...

imagensecforcepost.png
March 20, 2014

How easy would it be for a cyber criminal to gain control of a plane in mid-air?

We wanted to break down exactly how secure the navigation systems are on board commercial flights and do they pose a threat to security.

See more
imagensecforcepost.png
April 6, 2017

Firewall against firewall – bypassing an IPS

In this post we are going to explain how we used "iptables" to bypass an Intrusion Prevention System during a recent penetration test.

See more