Need tools/tips for a 2-3 hour after-hours physical/network audit (Team of 5, Univ. Class Project)
好的,我现在要帮用户总结这篇文章的内容。用户的要求是用中文,控制在100字以内,不需要特定的开头,直接写描述。 首先,我需要仔细阅读原文。这篇文章是一个学生写的,他在进行学校的安全审计。他有一个4-5人的团队,只有2-3小时的现场时间。现场还有其他同学也在做审计,可能会有网络干扰。他们带了Windows笔记本、Kali Linux笔记本和Flipper Zero等工具。 接下来,环境部分提到网络高度分段,使用了Cisco和FortiGate设备,无线网络有三种类型:BYOD、Guest和Secure。云服务器主要用Azure和AD,物理安全包括RFID门禁和摄像头。政策方面有USB未锁定、BIOS密码未轮换、教师不轮换密码等漏洞。 用户的问题是询问在有限时间内,如何利用工具和物理手段进行审计,并如何分配团队任务。 现在我需要将这些信息浓缩到100字以内。重点包括:学校安全审计、团队人数、时间限制、使用的工具、环境特点(如网络结构、无线类型)、政策漏洞(如USB未锁定)以及Flipper攻击的可能性。 确保语言简洁明了,直接描述内容,不使用“文章总结”之类的开头。 </think> 一位学生正在为信息安全课程进行学校安全审计,带领一个4-5人的团队,在2-3小时内利用Windows笔记本、Kali Linux和Flipper Zero等工具评估网络、无线和物理安全漏洞。 2026-2-25 00:8:2 Author: www.reddit.com(查看原文) 阅读量:22 收藏

Hey everyone,

I’m conducting an authorized security audit on a school for my Information Assurance and Security class. I have a team of 4-5 people, and we’ll only have about 2-3 hours on-site after hours. The rest of our class will also be there doing their own audits, so there might be some competing network noise. I need to prioritize our time efficiently and figure out how best to divide the work.

Our Loadout:

  • Windows Laptop

  • Kali Linux Laptop

  • Flipper Zero + Wi-Fi Dev Board (Momentum OS)

Rules of Engagement:

  • DO NOT break anything or cause downtime (they get immediate alerts if things drop).

The Environment / Recon Intel:

  • Network/Infra: Highly segmented. Cisco Layer 3 switches, 48 FortiGate firewalls, Graylog server. No 802.1x, NO port security.

  • Wireless: BYOD (faculty), Guest, and a Secure network (cert-based for laptops).

  • Cloud/Servers: Hybrid Azure, AD on-prem. Next to nothing else on-site besides AD. Veeam for the small on-prem footprint. Cloud heavily utilized (typical edu SIS apps, OneSync, etc.).

  • Endpoints: Students use Chromebooks. Teachers use Microsoft Surface 7s. SCCM and TeamViewer Enterprise for management/remote access.

  • Physical Security: Continuum RFID hardwired access, keypads. Classrooms use physical keys. Lots of IP-based cameras and door controllers.

  • Policies & Vulnerabilities:

    • Unlocked USB policy.

    • Unrotated BIOS passwords.

    • Teachers do not rotate passwords (and have to memorize them). Duo is used for MFA.

    • Lightspeed content filter (should block .exes) + blacklist site blocking.

    • Elementary school Chromebook carts are left unlocked.

Given the short 2-3 hour window, a team of 5, the lack of port security, and the unlocked USBs/Chromebook carts, what specific tools, payloads, or physical bypasses would you prioritize? How would you recommend splitting our team (e.g., who does physical vs. network)? Any specific Flipper attacks we should prep beforehand?

Thanks in advance!


文章来源: https://www.reddit.com/r/netsecstudents/comments/1rdxicf/need_toolstips_for_a_23_hour_afterhours/
如有侵权请联系:admin#unsafe.sh