UNIT 3: PENETRATION TESTING AND VULNERABILITY ANALYSIS
I. FOUNDATIONS & PRE-ENGAGEMENT
Legal, Ethical, and Professional Considerations
-
Impact on Decision-Making:
-
Legal Compliance: Tests must adhere to laws (e.g., Computer Fraud and Abuse Act in US, IT Act in India). Unauthorized testing is illegal.
-
Ethical Boundaries: Testers must operate within agreed scope to avoid disrupting business operations or accessing unauthorized data.
-
Professional Liability: Clear contracts and Rules of Engagement (ROE) protect both the tester (client) and the organization from legal repercussions.
-
Reputation Risk: A poorly scoped or executed test can damage organizational reputation and stakeholder trust.
-
-
Stakeholder Engagement:
-
Critical for Success: Engages management (for budget/approval), IT/security teams (for logistics), and legal/compliance (for risk mitigation).
-
Ensures Alignment: Guarantees test objectives match business risk priorities and resources are allocated correctly.
-
-
Rules of Engagement (ROE) & Scope Definition:
-
ROE: Formal document defining what, when, how, and who. Includes: testing windows, communication channels, prohibited actions (e.g., DoS), and data handling procedures.
-
Scope: Explicit list of in-scope and out-of-scope assets (IP ranges, applications, networks). Prevents "scope creep" and legal exposure.
-
[!TIP] Exam Focus: Always link legal/ethical considerations to organizational risk and decision-making. A test without proper ROE is illegal and unethical.
Types and Scoping of Penetration Tests
| Testing Type | Primary Focus | Key Considerations |
|---|---|---|
| Network Penetration Testing | Infrastructure (routers, firewalls, servers, network services). | Focus on network-level vulnerabilities (e.g., misconfigured services, weak firewall rules, unpatched OS). Requires knowledge of network protocols (TCP/IP, DNS, SMB). |
| Application Penetration Testing | Software applications (Web, Mobile, API). | Focus on application logic flaws (OWASP Top 10). Requires understanding of code, session management, and data flow. Often deeper, more targeted. |
| Black-Box | Tester has no prior knowledge of internal systems. | Simulates an external attacker. Relies heavily on reconnaissance. Time-consuming; may miss deeper vulnerabilities. |
| White-Box | Tester has full knowledge (source code, architecture docs, credentials). | Simulates an insider or advanced attacker with foothold. Most thorough and efficient. Focus on logic flaws and deep paths. |
| Gray-Box | Tester has partial knowledge (e.g., user-level credentials). | Most common real-world scenario. Balances efficiency and realism. Tests both external attack paths and internal privilege escalation. |
[!TIP] Exam Focus: Be ready to compare/contrast Network vs. App testing and Black/White/Gray-box methodologies. Know which scenario fits which type.
II. RECONNAISSANCE & INFORMATION GATHERING
Passive Reconnaissance
-
Purpose: Gather target information without directly interacting with the target systems, avoiding detection.
-
DNS Reconnaissance Techniques:
-
Zone Transfers: Attempt AXFR requests to retrieve entire DNS zone files (misconfiguration).
-
DNS Enumeration: Using tools (
dig,nslookup,dnsrecon) to query for subdomains, MX records, TXT records. -
DNS History: Using services like
SecurityTrails,DNSDumpsterto find historical DNS records and subdomains.
-
-
OSINT (Open-Source Intelligence):
-
External Presence: Search engines (Google Dorks), social media (LinkedIn, GitHub), public records, job postings, paste sites.
-
Goal: Build a footprint of the organization: employee names, technology stack, IP ranges, email formats, partner companies.
-
Active Reconnaissance & Target Analysis
-
Importance of Architecture Understanding:
-
Efficient Exploitation: Knowing OS, services, versions, and network topology helps select correct exploits and avoid crashing critical systems.
-
Attack Path Mapping: Identifies pivot points, trust relationships, and choke points.
-
Risk Assessment: Helps prioritize targets based on criticality (e.g., domain controller vs. print server).
-
-
Network Mapping & Service Enumeration:
-
Network Mapping: Tools like
Nmapto discover live hosts (-sP), OS detection (-O), and network topology (-traceroute). -
Service Enumeration: Identify open ports and running services (
-sV), and their versions. For web apps, enumerate directories/files (dirb,gobuster), parameters, and technologies (Wappalyzer).
-
[!TIP] Exam Focus: Link passive recon (OSINT/DNS) to footprinting and active recon (Nmap) to enumeration. Emphasize that architecture understanding prevents wasted effort and collateral damage.
III. VULNERABILITY ANALYSIS & SCANNING
Vulnerability Scanning Tools and Techniques
-
Categories & Use Cases:
-
Network Scanners:
Nessus,OpenVAS,Qualys. Scan networks for missing patches, misconfigurations, known vulnerabilities (CVEs). -
Web Scanners:
Burp Suite Professional,OWASP ZAP,Acunetix. Focus on web app flaws (SQLi, XSS, CSRF). -
Source Code Scanners:
SonarQube,Checkmarx,Fortify. Analyze source code for security anti-patterns (for white-box/DevSecOps).
-
-
Interpreting Results & False Positives:
-
False Positive: Scanner reports a vulnerability that does not exist in the specific context.
-
Manual Verification Required: Never trust scanner output blindly. Validate each finding:
-
Check if the vulnerable component/version is actually present.
-
Attempt to reproduce the vulnerability manually.
-
Assess real-world exploitability and impact (CVSS score is a guide, not gospel).
-
-
Web Application Penetration Testing Methodologies
-
OWASP Testing Guide Phases (v4.2): A structured, repeatable process.
-
Information Gathering: Passive/Active recon on the app.
-
Configuration & Deployment Management Testing: Check for verbose errors, outdated components, HTTP methods.
-
Identity Management Testing: Authentication, session management, authorization flaws.
-
Authentication Testing: Brute-force, credential stuffing, logic flaws.
-
Authorization Testing: Horizontal/Vertical privilege escalation, broken access control.
-
Session Management Testing: Cookie handling, session fixation/hijacking.
-
Input Validation Testing: SQLi, XSS, Command Injection, SSRF, XXE.
-
Business Logic Testing: Flaws in application workflows (e.g., price manipulation, race conditions).
-
Client-Side Testing: JavaScript security, DOM-based XSS, CORS misconfigurations.
-
Specific Deep Dive: SQL Injection (SQLi)
-
Primary Risk: Bypassing application authentication/authorization and direct, unauthorized access to, modification of, or deletion of backend database contents.
-
Attack Vectors & Impact:
-
In-band (Error-based, Union-based): Data exfiltration via same channel.
-
Inferential (Blind Boolean-based, Time-based): Data exfiltration via true/false responses or delays.
-
Out-of-band (OOB): Data exfiltration via different channel (e.g., DNS, HTTP requests to attacker server).
-
Impact: Data theft (PII, credentials), data loss, database takeover, potential for OS command execution (if DB user has high privileges).
-
Specific Deep Dive: HTTP Strict Transport Security (HSTS)
-
Purpose: Force all communication with the domain to use HTTPS only, preventing protocol downgrade attacks and cookie hijacking.
-
Security Enhancement Mechanism:
-
Server sends header:
Strict-Transport-Security: max-age=31536000; includeSubDomains; preload. -
Browser caches policy for
max-ageseconds. -
Future requests to the domain (and subdomains if
includeSubDomains) automatically usehttps://. -
Preload: Submission to Chrome/Firefox/Edge preload lists makes HTTPS mandatory on first visit.
-
-
Implementation Considerations & Risks of Not Using HSTS:
-
Implementation: Must be served over HTTPS initially.
max-ageshould be reasonable (start small, increase).includeSubDomainsrequires all subdomains to support HTTPS. -
Risks of NOT Using HSTS:
-
SSL Stripping: Attacker downgrades HTTPS to HTTP, intercepting traffic.
-
Cookie Theft: Session cookies sent over HTTP can be stolen.
-
User Error: Users manually typing
http://bypass security.
-
-
[!TIP] Exam Focus: For SQLi, state the primary risk (DB access) and list attack types. For HSTS, explain the header mechanism and consequences of absence (SSL stripping).
IV. EXPLOITATION & ATTACK VECTORS
Web Application Exploitation
-
Exploiting Identified Vulnerabilities:
-
SQLi: Use tools (
sqlmap) or manual techniques to extract databases, bypass logins, or execute OS commands. -
Authentication Flaws: Exploit weak password policies, credential stuffing, broken password reset logic, or session fixation.
-
XSS: Steal session cookies, perform phishing, deface pages, or deliver malware.
-
CSRF: Forge requests to change user state (email, password, funds transfer) without consent.
-
File Inclusion: Local/Remote File Inclusion (LFI/RFI) to read sensitive files or execute remote code.
-
Deserialization: Exploit unsafe deserialization to achieve Remote Code Execution (RCE).
-
Wireless Network Penetration Testing
-
Importance of Packet Sniffing:
-
Capture Unencrypted Traffic: Reveals credentials (HTTP, FTP), cookies, and sensitive data in clear text.
-
Protocol Analysis: Identifies client devices, access points, and communication patterns.
-
Attack Preparation: Captures handshakes (for WPA2 cracking) and discovers hidden SSIDs.
-
Tools:
Wireshark,airodump-ng.
-
-
Common Social Engineering Tactics for Wireless:
-
Evil Twin Attack: Rogue AP mimicking legitimate one to lure clients; used for credential harvesting or MITM.
-
Rogue AP with Same SSID: Client automatically connects if signal stronger; attacker intercepts traffic.
-
Phishing via Captive Portal: Fake login page for "free WiFi" to steal credentials.
-
-
Wireless Encryption & Protocol Weaknesses:
-
WEP: Cryptographically broken. Weak IVs allow key recovery in minutes with tools (
aircrack-ng). -
WPA/WPA2-Personal (PSK): Vulnerable to offline dictionary/brute-force attacks if a 4-way handshake is captured. Weak passwords are easily cracked.
-
WPA/WPA2-Enterprise (EAP): Vulnerable to misconfiguration (e.g., weak EAP methods like PEAP without server cert validation) and credential theft via rogue APs.
-
Cryptography in Security & Attacks
-
RSA Algorithm for Secure Communication:
-
Key Generation:
-
Choose large primes $p$, $q$.
-
Compute $$\displaystyle n = p \times q $$, $$\displaystyle \phi(n) = (p-1)(q-1) $$.
-
Choose public exponent $e$ such that $$\displaystyle 1 < e < \phi(n) $$ and $$\displaystyle \gcd(e, \phi(n)) = 1 $$.
-
Compute private exponent $d$ such that $$\displaystyle d \equiv e^{-1} \pmod{\phi(n)} $$.
-
-
Encryption (by sender with receiver's public key): $$\displaystyle C = M^e \bmod n $$
-
Decryption (by receiver with private key): $$\displaystyle M = C^d \bmod n $$
-
Purpose: Provides confidentiality (encryption) and digital signatures (sign with private key, verify with public key).
-
-
Concepts of Decryption in Attacks:
-
Cryptanalysis: Breaking encryption without the key (e.g., factoring $n$ in RSA, exploiting weak ciphers).
-
Key Recovery Attacks: Stealing or brute-forcing the private key.
-
Side-Channel Attacks: Exploiting implementation flaws (timing, power consumption) to derive key.
-
Man-in-the-Middle (MitM): Intercepting and potentially altering encrypted traffic if certificate validation is bypassed.
-
-
Cryptographic Audits & Common Failures:
-
Audit Focus: Algorithm choice, key length, key management, IV/nonce reuse, protocol implementation, certificate validation.
-
Common Failures:
-
Using deprecated algorithms (MD5, SHA-1, RC4, DES).
-
Insufficient key length (e.g., RSA < 2048-bit).
-
Hardcoded keys in source code.
-
Improper certificate validation (accepting self-signed certs).
-
Reusing IVs/nonces in CBC/CTR modes (leading to plaintext recovery).
-
-
[!TIP] Exam Focus: For RSA, be able to write the encryption/decryption formulas. For cryptography audit, list common failures (weak algos, key mgmt).
V. SOCIAL ENGINEERING & HUMAN FACTOR
Social Engineering Attack Lifecycle
-
Research (Recon): Gather target info (OSINT, dumpster diving).
-
Hook (Initiate Contact): Establish rapport via email, phone, or in-person (pretexting).
-
Play (Exploit): Create sense of urgency, fear, or trust to manipulate action (e.g., click link, disclose password).
-
Exit (Cover Tracks): Disengage, remove evidence, maintain access if needed.
-
Tactics Targeting Employees & Network Access:
-
Phishing: Broad emails with malicious links/attachments.
-
Spear Phishing: Highly targeted, personalized emails.
-
Whaling: Spear phishing targeting high-value executives.
-
Vishing/Smishing: Voice calls/SMS messages for credential harvesting.
-
Baiting: Leaving infected USB drives in public areas.
-
-
Specific Tactics for Wireless Compromise:
-
Rogue AP (Evil Twin): As above, tricking users to connect.
-
"Free Public WiFi": Luring users to connect to a malicious hotspot.
-
Pretexting as IT Support: Calling employees to " troubleshoot WiFi" and get them to install malware or reveal credentials.
-
Mitigation Strategies
-
Role of Employee Training Programs:
-
Awareness: Teach common tactics (phishing indicators, suspicious links).
-
Simulation: Conduct regular, realistic phishing simulations to reinforce training.
-
Reporting: Establish clear, non-punitive channels for reporting suspicious activity.
-
Policy Enforcement: Clear policies on data handling, password sharing, and device usage.
-
-
Building a Security-Aware Culture:
-
Leadership Buy-in: Management must model secure behavior.
-
Continuous Reinforcement: Regular updates, reminders, and refresher courses (not one-time annual training).
-
Positive Reinforcement: Reward secure behavior and reporting.
-
Integration: Security awareness as part of onboarding and daily operations.
-
[!TIP] Exam Focus: Know the lifecycle stages. Link wireless social engineering to rogue APs. Emphasize that training + culture is the defense, not just technology.
V. POST-EXPLOITATION, REPORTING & SPECIALIZED CONTEXTS
Documentation and Reporting
-
Key Elements of a Penetration Test Report:
-
Executive Summary: High-level overview for management (business risk, key findings, overall posture).
-
Scope & Methodology: What was tested, rules of engagement, tools/standards used (e.g., OWASP, PTES).
-
Detailed Findings: For each vulnerability:
-
Title & Severity (CVSS score).
-
Description: What it is.
-
Evidence: Screenshots, curl commands, payloads.
-
Impact: Business/technical consequences.
-
Remediation: Clear, actionable steps (prioritized: Critical/High/Med/Low).
-
-
Conclusion & Recommendations: Strategic advice, roadmap for remediation.
-
-
Specific Elements for a Cryptography Audit Report:
-
Algorithm Inventory: List of all cryptographic algorithms in use.
-
Key Management Assessment: Storage, rotation, destruction policies.
-
Protocol Configuration: TLS/SSL versions, cipher suites, certificate validation.
-
Implementation Review: Code review for crypto misuse (e.g., ECB mode, hardcoded keys).
-
Compliance Check: Against standards (PCI-DSS, NIST, GDPR).
-
-
Communicating to Stakeholders:
-
Technical (Devs/SysAdmins): Detailed steps, code snippets, configuration fixes.
-
Non-Technical (Management): Business impact, risk to reputation/finance, cost of remediation vs. cost of breach. Avoid jargon.
-
Specialized Penetration Testing Scenarios
-
Cloud Security Penetration Testing:
-
Unique Challenges & Attack Surfaces:
-
Shared Responsibility Model: Tester must understand what is provider's vs. client's responsibility.
-
Dynamic Environments: Auto-scaling, ephemeral instances.
-
API-Centric: Heavy reliance on cloud provider APIs (AWS, Azure, GCP).
-
Misconfigurations: The #1 risk (e.g., S3 buckets public, security groups too permissive, IAM roles overly privileged).
-
-
Cloud-Specific Misconfigurations:
-
Public storage (S3, Blob).
-
Default/weak credentials on cloud services.
-
Exposed management consoles (AWS Console, Azure Portal).
-
Unrestricted inbound/outbound traffic in security groups/NSGs.
-
Lack of logging/monitoring (CloudTrail, Azure Monitor).
-
-
-
Case Study Analysis: rgpvonline.com
-
Applying Pen Test Objectives to a Public-Facing Website:
-
Scope: Clearly define in-scope:
rgpvonline.comdomain, all subdomains, associated APIs. Out-of-scope: Third-party services, internal IPs. -
Methodology: Follow OWASP Web Testing Guide.
-
Key Focus Areas:
-
Authentication & Session: Student/Admin login portals, password reset, session fixation.
-
Data Exposure: Student records, exam results, personal info (PII) - check for IDOR, insecure direct object references.
-
Input Validation: Search, feedback, file upload forms for SQLi, XSS, File Inclusion.
-
Configuration: Server headers, error messages, backup files (.bak, .sql), directory listing.
-
Business Logic: Can a student view another's results? Can grades be manipulated?
-
-
-
Scoping for Public Website: Emphasize no DoS, no data destruction, strict adherence to ROE to avoid disrupting educational services.
-
Capture the Flag (CTF) Competitions
-
Simulation of Real-World Scenarios:
-
Varied Challenges: Pwn (binary exploitation), Web (SQLi, XSS, logic flaws), Crypto (breaking weak crypto), Forensics (file analysis), Reversing (malware/assembly), OSINT (real-world info gathering).
-
Time Pressure & Resource Constraints: Mimics real incident response or pentest deadlines.
-
Unknown Environment: "Black-box" challenges require creative recon and problem-solving.
-
-
Educational Value & Skill Development:
-
Hands-On Learning: Applies theoretical knowledge to practical, vulnerable systems.
-
Skill Diversification: Exposes players to multiple security domains.
-
Community & Competition: Fosters collaboration, knowledge sharing, and benchmarks skills globally.
-
Career Pathway: Used by employers to assess practical skills; top performers often recruited.
-
[!TIP] Exam Focus: For cloud security, list misconfigurations (S3 public, IAM). For rgpvonline.com, propose a methodology (OWASP) and specific web flaws to check (IDOR for student data). For CTF, link challenge types to real-world skills.
END OF UNIT 3 NOTES