Skip to content
CY-702 (A) · Penetration Testing and Vulnerability Analysis/Quick Revision Short Notes

Penetration Testing and Vulnerability Analysis (CY-702 (A)) - Unit 3 Short Notes

UNIT 3: PENETRATION TESTING AND VULNERABILITY ANALYSIS


I. FOUNDATIONS & PRE-ENGAGEMENT

Legal, Ethical, and Professional Considerations

  • Impact on Decision-Making:

    • Legal Compliance: Tests must adhere to laws (e.g., Computer Fraud and Abuse Act in US, IT Act in India). Unauthorized testing is illegal.

    • Ethical Boundaries: Testers must operate within agreed scope to avoid disrupting business operations or accessing unauthorized data.

    • Professional Liability: Clear contracts and Rules of Engagement (ROE) protect both the tester (client) and the organization from legal repercussions.

    • Reputation Risk: A poorly scoped or executed test can damage organizational reputation and stakeholder trust.

  • Stakeholder Engagement:

    • Critical for Success: Engages management (for budget/approval), IT/security teams (for logistics), and legal/compliance (for risk mitigation).

    • Ensures Alignment: Guarantees test objectives match business risk priorities and resources are allocated correctly.

  • Rules of Engagement (ROE) & Scope Definition:

    • ROE: Formal document defining what, when, how, and who. Includes: testing windows, communication channels, prohibited actions (e.g., DoS), and data handling procedures.

    • Scope: Explicit list of in-scope and out-of-scope assets (IP ranges, applications, networks). Prevents "scope creep" and legal exposure.

[!TIP] Exam Focus: Always link legal/ethical considerations to organizational risk and decision-making. A test without proper ROE is illegal and unethical.

Types and Scoping of Penetration Tests

Testing Type Primary Focus Key Considerations
Network Penetration Testing Infrastructure (routers, firewalls, servers, network services). Focus on network-level vulnerabilities (e.g., misconfigured services, weak firewall rules, unpatched OS). Requires knowledge of network protocols (TCP/IP, DNS, SMB).
Application Penetration Testing Software applications (Web, Mobile, API). Focus on application logic flaws (OWASP Top 10). Requires understanding of code, session management, and data flow. Often deeper, more targeted.
Black-Box Tester has no prior knowledge of internal systems. Simulates an external attacker. Relies heavily on reconnaissance. Time-consuming; may miss deeper vulnerabilities.
White-Box Tester has full knowledge (source code, architecture docs, credentials). Simulates an insider or advanced attacker with foothold. Most thorough and efficient. Focus on logic flaws and deep paths.
Gray-Box Tester has partial knowledge (e.g., user-level credentials). Most common real-world scenario. Balances efficiency and realism. Tests both external attack paths and internal privilege escalation.

[!TIP] Exam Focus: Be ready to compare/contrast Network vs. App testing and Black/White/Gray-box methodologies. Know which scenario fits which type.


II. RECONNAISSANCE & INFORMATION GATHERING

Passive Reconnaissance

  • Purpose: Gather target information without directly interacting with the target systems, avoiding detection.

  • DNS Reconnaissance Techniques:

    • Zone Transfers: Attempt AXFR requests to retrieve entire DNS zone files (misconfiguration).

    • DNS Enumeration: Using tools (dig, nslookup, dnsrecon) to query for subdomains, MX records, TXT records.

    • DNS History: Using services like SecurityTrails, DNSDumpster to find historical DNS records and subdomains.

  • OSINT (Open-Source Intelligence):

    • External Presence: Search engines (Google Dorks), social media (LinkedIn, GitHub), public records, job postings, paste sites.

    • Goal: Build a footprint of the organization: employee names, technology stack, IP ranges, email formats, partner companies.

Active Reconnaissance & Target Analysis

  • Importance of Architecture Understanding:

    • Efficient Exploitation: Knowing OS, services, versions, and network topology helps select correct exploits and avoid crashing critical systems.

    • Attack Path Mapping: Identifies pivot points, trust relationships, and choke points.

    • Risk Assessment: Helps prioritize targets based on criticality (e.g., domain controller vs. print server).

  • Network Mapping & Service Enumeration:

    • Network Mapping: Tools like Nmap to discover live hosts (-sP), OS detection (-O), and network topology (-traceroute).

    • Service Enumeration: Identify open ports and running services (-sV), and their versions. For web apps, enumerate directories/files (dirb, gobuster), parameters, and technologies (Wappalyzer).

[!TIP] Exam Focus: Link passive recon (OSINT/DNS) to footprinting and active recon (Nmap) to enumeration. Emphasize that architecture understanding prevents wasted effort and collateral damage.


III. VULNERABILITY ANALYSIS & SCANNING

Vulnerability Scanning Tools and Techniques

  • Categories & Use Cases:

    • Network Scanners: Nessus, OpenVAS, Qualys. Scan networks for missing patches, misconfigurations, known vulnerabilities (CVEs).

    • Web Scanners: Burp Suite Professional, OWASP ZAP, Acunetix. Focus on web app flaws (SQLi, XSS, CSRF).

    • Source Code Scanners: SonarQube, Checkmarx, Fortify. Analyze source code for security anti-patterns (for white-box/DevSecOps).

  • Interpreting Results & False Positives:

    • False Positive: Scanner reports a vulnerability that does not exist in the specific context.

    • Manual Verification Required: Never trust scanner output blindly. Validate each finding:

      1. Check if the vulnerable component/version is actually present.

      2. Attempt to reproduce the vulnerability manually.

      3. Assess real-world exploitability and impact (CVSS score is a guide, not gospel).

Web Application Penetration Testing Methodologies

  • OWASP Testing Guide Phases (v4.2): A structured, repeatable process.

    1. Information Gathering: Passive/Active recon on the app.

    2. Configuration & Deployment Management Testing: Check for verbose errors, outdated components, HTTP methods.

    3. Identity Management Testing: Authentication, session management, authorization flaws.

    4. Authentication Testing: Brute-force, credential stuffing, logic flaws.

    5. Authorization Testing: Horizontal/Vertical privilege escalation, broken access control.

    6. Session Management Testing: Cookie handling, session fixation/hijacking.

    7. Input Validation Testing: SQLi, XSS, Command Injection, SSRF, XXE.

    8. Business Logic Testing: Flaws in application workflows (e.g., price manipulation, race conditions).

    9. Client-Side Testing: JavaScript security, DOM-based XSS, CORS misconfigurations.

Specific Deep Dive: SQL Injection (SQLi)

  • Primary Risk: Bypassing application authentication/authorization and direct, unauthorized access to, modification of, or deletion of backend database contents.

  • Attack Vectors & Impact:

    • In-band (Error-based, Union-based): Data exfiltration via same channel.

    • Inferential (Blind Boolean-based, Time-based): Data exfiltration via true/false responses or delays.

    • Out-of-band (OOB): Data exfiltration via different channel (e.g., DNS, HTTP requests to attacker server).

    • Impact: Data theft (PII, credentials), data loss, database takeover, potential for OS command execution (if DB user has high privileges).

Specific Deep Dive: HTTP Strict Transport Security (HSTS)

  • Purpose: Force all communication with the domain to use HTTPS only, preventing protocol downgrade attacks and cookie hijacking.

  • Security Enhancement Mechanism:

    1. Server sends header: Strict-Transport-Security: max-age=31536000; includeSubDomains; preload.

    2. Browser caches policy for max-age seconds.

    3. Future requests to the domain (and subdomains if includeSubDomains) automatically use https://.

    4. Preload: Submission to Chrome/Firefox/Edge preload lists makes HTTPS mandatory on first visit.

  • Implementation Considerations & Risks of Not Using HSTS:

    • Implementation: Must be served over HTTPS initially. max-age should be reasonable (start small, increase). includeSubDomains requires all subdomains to support HTTPS.

    • Risks of NOT Using HSTS:

      • SSL Stripping: Attacker downgrades HTTPS to HTTP, intercepting traffic.

      • Cookie Theft: Session cookies sent over HTTP can be stolen.

      • User Error: Users manually typing http:// bypass security.

[!TIP] Exam Focus: For SQLi, state the primary risk (DB access) and list attack types. For HSTS, explain the header mechanism and consequences of absence (SSL stripping).


IV. EXPLOITATION & ATTACK VECTORS

Web Application Exploitation

  • Exploiting Identified Vulnerabilities:

    • SQLi: Use tools (sqlmap) or manual techniques to extract databases, bypass logins, or execute OS commands.

    • Authentication Flaws: Exploit weak password policies, credential stuffing, broken password reset logic, or session fixation.

    • XSS: Steal session cookies, perform phishing, deface pages, or deliver malware.

    • CSRF: Forge requests to change user state (email, password, funds transfer) without consent.

    • File Inclusion: Local/Remote File Inclusion (LFI/RFI) to read sensitive files or execute remote code.

    • Deserialization: Exploit unsafe deserialization to achieve Remote Code Execution (RCE).

Wireless Network Penetration Testing

  • Importance of Packet Sniffing:

    • Capture Unencrypted Traffic: Reveals credentials (HTTP, FTP), cookies, and sensitive data in clear text.

    • Protocol Analysis: Identifies client devices, access points, and communication patterns.

    • Attack Preparation: Captures handshakes (for WPA2 cracking) and discovers hidden SSIDs.

    • Tools: Wireshark, airodump-ng.

  • Common Social Engineering Tactics for Wireless:

    1. Evil Twin Attack: Rogue AP mimicking legitimate one to lure clients; used for credential harvesting or MITM.

    2. Rogue AP with Same SSID: Client automatically connects if signal stronger; attacker intercepts traffic.

    3. Phishing via Captive Portal: Fake login page for "free WiFi" to steal credentials.

  • Wireless Encryption & Protocol Weaknesses:

    • WEP: Cryptographically broken. Weak IVs allow key recovery in minutes with tools (aircrack-ng).

    • WPA/WPA2-Personal (PSK): Vulnerable to offline dictionary/brute-force attacks if a 4-way handshake is captured. Weak passwords are easily cracked.

    • WPA/WPA2-Enterprise (EAP): Vulnerable to misconfiguration (e.g., weak EAP methods like PEAP without server cert validation) and credential theft via rogue APs.

Cryptography in Security & Attacks

  • RSA Algorithm for Secure Communication:

    • Key Generation:

      1. Choose large primes $p$, $q$.

      2. Compute $$\displaystyle n = p \times q $$, $$\displaystyle \phi(n) = (p-1)(q-1) $$.

      3. Choose public exponent $e$ such that $$\displaystyle 1 < e < \phi(n) $$ and $$\displaystyle \gcd(e, \phi(n)) = 1 $$.

      4. Compute private exponent $d$ such that $$\displaystyle d \equiv e^{-1} \pmod{\phi(n)} $$.

    • Encryption (by sender with receiver's public key): $$\displaystyle C = M^e \bmod n $$

    • Decryption (by receiver with private key): $$\displaystyle M = C^d \bmod n $$

    • Purpose: Provides confidentiality (encryption) and digital signatures (sign with private key, verify with public key).

  • Concepts of Decryption in Attacks:

    • Cryptanalysis: Breaking encryption without the key (e.g., factoring $n$ in RSA, exploiting weak ciphers).

    • Key Recovery Attacks: Stealing or brute-forcing the private key.

    • Side-Channel Attacks: Exploiting implementation flaws (timing, power consumption) to derive key.

    • Man-in-the-Middle (MitM): Intercepting and potentially altering encrypted traffic if certificate validation is bypassed.

  • Cryptographic Audits & Common Failures:

    • Audit Focus: Algorithm choice, key length, key management, IV/nonce reuse, protocol implementation, certificate validation.

    • Common Failures:

      • Using deprecated algorithms (MD5, SHA-1, RC4, DES).

      • Insufficient key length (e.g., RSA < 2048-bit).

      • Hardcoded keys in source code.

      • Improper certificate validation (accepting self-signed certs).

      • Reusing IVs/nonces in CBC/CTR modes (leading to plaintext recovery).

[!TIP] Exam Focus: For RSA, be able to write the encryption/decryption formulas. For cryptography audit, list common failures (weak algos, key mgmt).


V. SOCIAL ENGINEERING & HUMAN FACTOR

Social Engineering Attack Lifecycle

  1. Research (Recon): Gather target info (OSINT, dumpster diving).

  2. Hook (Initiate Contact): Establish rapport via email, phone, or in-person (pretexting).

  3. Play (Exploit): Create sense of urgency, fear, or trust to manipulate action (e.g., click link, disclose password).

  4. Exit (Cover Tracks): Disengage, remove evidence, maintain access if needed.

  • Tactics Targeting Employees & Network Access:

    • Phishing: Broad emails with malicious links/attachments.

    • Spear Phishing: Highly targeted, personalized emails.

    • Whaling: Spear phishing targeting high-value executives.

    • Vishing/Smishing: Voice calls/SMS messages for credential harvesting.

    • Baiting: Leaving infected USB drives in public areas.

  • Specific Tactics for Wireless Compromise:

    • Rogue AP (Evil Twin): As above, tricking users to connect.

    • "Free Public WiFi": Luring users to connect to a malicious hotspot.

    • Pretexting as IT Support: Calling employees to " troubleshoot WiFi" and get them to install malware or reveal credentials.

Mitigation Strategies

  • Role of Employee Training Programs:

    • Awareness: Teach common tactics (phishing indicators, suspicious links).

    • Simulation: Conduct regular, realistic phishing simulations to reinforce training.

    • Reporting: Establish clear, non-punitive channels for reporting suspicious activity.

    • Policy Enforcement: Clear policies on data handling, password sharing, and device usage.

  • Building a Security-Aware Culture:

    • Leadership Buy-in: Management must model secure behavior.

    • Continuous Reinforcement: Regular updates, reminders, and refresher courses (not one-time annual training).

    • Positive Reinforcement: Reward secure behavior and reporting.

    • Integration: Security awareness as part of onboarding and daily operations.

[!TIP] Exam Focus: Know the lifecycle stages. Link wireless social engineering to rogue APs. Emphasize that training + culture is the defense, not just technology.


V. POST-EXPLOITATION, REPORTING & SPECIALIZED CONTEXTS

Documentation and Reporting

  • Key Elements of a Penetration Test Report:

    1. Executive Summary: High-level overview for management (business risk, key findings, overall posture).

    2. Scope & Methodology: What was tested, rules of engagement, tools/standards used (e.g., OWASP, PTES).

    3. Detailed Findings: For each vulnerability:

      • Title & Severity (CVSS score).

      • Description: What it is.

      • Evidence: Screenshots, curl commands, payloads.

      • Impact: Business/technical consequences.

      • Remediation: Clear, actionable steps (prioritized: Critical/High/Med/Low).

    4. Conclusion & Recommendations: Strategic advice, roadmap for remediation.

  • Specific Elements for a Cryptography Audit Report:

    • Algorithm Inventory: List of all cryptographic algorithms in use.

    • Key Management Assessment: Storage, rotation, destruction policies.

    • Protocol Configuration: TLS/SSL versions, cipher suites, certificate validation.

    • Implementation Review: Code review for crypto misuse (e.g., ECB mode, hardcoded keys).

    • Compliance Check: Against standards (PCI-DSS, NIST, GDPR).

  • Communicating to Stakeholders:

    • Technical (Devs/SysAdmins): Detailed steps, code snippets, configuration fixes.

    • Non-Technical (Management): Business impact, risk to reputation/finance, cost of remediation vs. cost of breach. Avoid jargon.

Specialized Penetration Testing Scenarios

  • Cloud Security Penetration Testing:

    • Unique Challenges & Attack Surfaces:

      • Shared Responsibility Model: Tester must understand what is provider's vs. client's responsibility.

      • Dynamic Environments: Auto-scaling, ephemeral instances.

      • API-Centric: Heavy reliance on cloud provider APIs (AWS, Azure, GCP).

      • Misconfigurations: The #1 risk (e.g., S3 buckets public, security groups too permissive, IAM roles overly privileged).

    • Cloud-Specific Misconfigurations:

      • Public storage (S3, Blob).

      • Default/weak credentials on cloud services.

      • Exposed management consoles (AWS Console, Azure Portal).

      • Unrestricted inbound/outbound traffic in security groups/NSGs.

      • Lack of logging/monitoring (CloudTrail, Azure Monitor).

  • Case Study Analysis: rgpvonline.com

    • Applying Pen Test Objectives to a Public-Facing Website:

      1. Scope: Clearly define in-scope: rgpvonline.com domain, all subdomains, associated APIs. Out-of-scope: Third-party services, internal IPs.

      2. Methodology: Follow OWASP Web Testing Guide.

      3. Key Focus Areas:

        • Authentication & Session: Student/Admin login portals, password reset, session fixation.

        • Data Exposure: Student records, exam results, personal info (PII) - check for IDOR, insecure direct object references.

        • Input Validation: Search, feedback, file upload forms for SQLi, XSS, File Inclusion.

        • Configuration: Server headers, error messages, backup files (.bak, .sql), directory listing.

        • Business Logic: Can a student view another's results? Can grades be manipulated?

    • Scoping for Public Website: Emphasize no DoS, no data destruction, strict adherence to ROE to avoid disrupting educational services.

Capture the Flag (CTF) Competitions

  • Simulation of Real-World Scenarios:

    • Varied Challenges: Pwn (binary exploitation), Web (SQLi, XSS, logic flaws), Crypto (breaking weak crypto), Forensics (file analysis), Reversing (malware/assembly), OSINT (real-world info gathering).

    • Time Pressure & Resource Constraints: Mimics real incident response or pentest deadlines.

    • Unknown Environment: "Black-box" challenges require creative recon and problem-solving.

  • Educational Value & Skill Development:

    • Hands-On Learning: Applies theoretical knowledge to practical, vulnerable systems.

    • Skill Diversification: Exposes players to multiple security domains.

    • Community & Competition: Fosters collaboration, knowledge sharing, and benchmarks skills globally.

    • Career Pathway: Used by employers to assess practical skills; top performers often recruited.

[!TIP] Exam Focus: For cloud security, list misconfigurations (S3 public, IAM). For rgpvonline.com, propose a methodology (OWASP) and specific web flaws to check (IDOR for student data). For CTF, link challenge types to real-world skills.


END OF UNIT 3 NOTES

Go to where you left off?

Quick Add to Notes

Save questions, your own notes and screenshots into notes filed by unit. It takes a free account.

Create free account

Have an account? Log in