Discovering the attack area
What is an outsider’s view of your company from a technical viewpoint? The first stage in security testing is working out your public presence, which is your attack area. You most likely run many public machines both for your company and the product you provide. Even if you only have a website, that is your attack area.
Are you sure about which machines are public? Search for all the records under your primary domain. DNS records are easy to add but difficult to remove – it is hard to be sure they’re not used by some rare but essential service. They tend to accrue over time, so if you are in a mature company, there may be many. Scan them all to see whether a machine is running on that address. Anything you find in your scan is part of your attack area.
Similar logic applies to any public IP ranges your company owns and runs. Some of these may be directly related to running your product, while others may host internal machines for...