UNIT 4: PENETRATION TESTING AND VULNERABILITY ANALYSIS
1.0 PRE-ENGAGEMENT & LEGAL/ETHICAL FOUNDATIONS
1.1 Legal and Ethical Considerations
-
Legal Impact on Decision-Making:
-
Authorization: Written, scope-defined consent is mandatory. Without it, testing is illegal (Computer Fraud and Abuse Act, IT Act 2000).
-
Compliance: Tests must align with regulations (GDPR, HIPAA, PCI-DSS) to avoid regulatory penalties.
-
Liability: Defines responsibility for accidental system disruption or data exposure.
-
-
Ethical Boundaries & Professional Conduct:
-
Adherence to codes (e.g., (ISC)² Code of Ethics, OSSTMM).
-
Confidentiality: Protecting client data and findings.
-
Integrity: Honest reporting of all findings, including null results.
-
Scope Adherence: Never exceed defined boundaries.
-
[!TIP] Exam Focus: Questions often ask to evaluate impact. Link legal/ethical factors directly to organizational risk, reputation, and financial liability.
1.2 Scoping and Types of Penetration Tests
| Aspect | Network Penetration Testing | Application Penetration Testing |
|---|---|---|
| Primary Use Case | Testing infrastructure security (firewalls, routers, servers, internal network). | Testing software logic flaws (web apps, mobile apps, APIs). |
| Scope | External (Internet-facing) & Internal (post-breach simulation). | OWASP Top 10 focus (Injection, XSS, Broken Auth, etc.). |
| Key Tools | Nmap, Metasploit, Nessus (network scans). | Burp Suite, OWASP ZAP, Nikto, sqlmap. |
| Risk Profile | Focus on lateral movement, pivot points, service exploitation. | Focus on data exfiltration, session hijacking, business logic flaws. |
[!TIP] Comparative Analysis: For a 7m question, create a two-column table in your answer highlighting Scope, Tools, and Primary Risk for each type.
2.0 RECONNAISSANCE & INFORMATION GATHERING
2.1 DNS Reconnaissance
-
Purpose: Map the target's digital footprint, identify attack surface (subdomains, servers), and uncover infrastructure details.
-
Key Techniques:
-
Zone Transfer (AXFR): Attempt unauthorized transfer of entire DNS zone file (
dig @ns1.target.com target.com AXFR). -
Enumeration: Querying for common records (A, AAAA, MX, TXT, SRV).
-
Subdomain Discovery: Using wordlists, search engines, certificate transparency logs (crt.sh), and tools like
sublist3r,amass.
-
-
Methodology: Passive (search engines, public databases) → Active (direct queries to DNS servers).
2.2 External Presence & OSINT
-
Critical Pre-engagement Step: Reveals information the organization itself has published.
-
Key OSINT Sources:
-
Public Records: WHOIS, DNS records, business registries.
-
Social Media & Job Postings: Reveal tech stack, employee names (for phishing), office locations.
-
Certificate Transparency Logs: Discover subdomains via SSL/TLS certificates.
-
Code Repositories (GitHub): Often leak configuration files, API keys, internal IPs.
-
2.3 Target System Architecture Analysis
-
Why Crucial Before Exploitation?
-
Prevents "shooting in the dark" and unnecessary system crashes.
-
Identifies critical systems, trust relationships, and choke points.
-
Maps potential attack paths (e.g., "Compromise DMZ web server → pivot to internal DB server").
-
-
Analysis Focus:
-
Network topology diagrams (if available).
-
System dependencies (which apps talk to which databases?).
-
Entry/exit points for data (firewall rules, proxy configurations).
-
[!TIP] Common Pitfall: Skipping architecture analysis leads to wasted effort, missed high-value targets, and increased detection risk.
3.0 VULNERABILITY ANALYSIS & SCANNING
3.1 Vulnerability Scanning Tools
| Category | Purpose | Key Tools | Output Interpretation |
|---|---|---|---|
| Network-Based | Scan IP ranges for open ports, services, vulnerabilities. | Nessus, OpenVAS, Qualys. | CVSS Score: Prioritize severity. False Positives: Manual verification required. |
| Host-Based | Assess configuration of a specific system (OS, patches). | Lynis (Linux), Microsoft Baseline Security Analyzer. | Check for missing patches, insecure configs. |
| Web Application | Crawl and test web apps for OWASP flaws. | Burp Suite Scanner, Nikto, Acunetix. | High False Positive Rate: Requires manual validation of findings like XSS/SQLi. |
3.2 Web Application Penetration Testing Methodologies
-
Structured Frameworks: OWASP Testing Guide (most common), PTES (Penetration Testing Execution Standard).
-
Standard Phases:
-
Discovery: Passive/active info gathering, mapping app structure.
-
Analysis: Identify vulnerabilities (automated + manual).
-
Attack: Exploit confirmed vulnerabilities to assess impact (e.g., extract data, escalate privileges).
-
Reporting: Document findings, evidence, and remediation.
-
-
Key Testing Areas: Authentication, Session Management, Input Validation (SQLi, XSS), Access Control, API Security.
4.0 EXPLOITATION & ATTACK VECTORS
4.1 Web Application Security Vulnerabilities
-
SQL Injection (SQLi):
-
Primary Risk: Data Exfiltration (steal entire databases), Authentication Bypass, Data Manipulation/Deletion.
-
Types: Error-based, Union-based, Blind (Boolean/Time-based).
-
Mitigation: Prepared Statements (Parameterized Queries), Input Validation, Least Privilege DB accounts.
-
-
HTTP Strict Transport Security (HSTS):
-
Crucial Role: Server header
Strict-Transport-Security: max-age=...forces browsers to only use HTTPS. -
Prevents: Protocol downgrade attacks (SSL Stripping) and cookie hijacking via man-in-the-middle.
-
4.2 Wireless Penetration Testing
-
Packet Sniffing Importance:
-
Capture WPA/WPA2 handshakes for offline cracking.
-
Analyze traffic for plaintext protocols (HTTP, FTP, Telnet).
-
Identify misconfigurations (open networks, weak encryption like WEP).
-
-
Tools:
Wireshark(analysis),aircrack-ngsuite (airodump-ng,aireplay-ng) for handshake capture & cracking.
4.3 Social Engineering (Wireless & General)
-
Common Tactics Targeting Wireless:
-
Rogue Access Points (Evil Twin): Mimic legitimate SSID to trick users into connecting.
-
Phishing for Credentials: Fake captive portal ("Enter Wi-Fi password") to harvest credentials.
-
Wireless Phishing (Wi-Fi Phishing): Sending targeted emails about "network issues" to lure credential disclosure.
-
-
Employee Training Programs as Mitigation:
-
Awareness: Teach tactics (rogue APs, phishing cues).
-
Simulation Exercises: Regular, controlled phishing tests.
-
Reporting Culture: Encourage employees to report suspicious activity/APs.
-
Policy Enforcement: Clear rules on connecting to unknown networks.
-
4.4 Cryptography in Penetration Testing
-
RSA Algorithm for Secure Communication:
-
Purpose: Asymmetric encryption for key exchange (e.g., in TLS) and digital signatures.
-
Process:
- Key Generation:
-
$$n = p \times q$$
$$\phi(n) = (p-1)(q-1)$$
Choose $e$ (public exponent), compute $d$ (private exponent) such that $e \cdot d \equiv 1 \mod \phi(n)$.
2. **Encryption (by sender with *public* key $(n, e)$):**
$$C = M^e \mod n$$
3. **Decryption (by receiver with *private* key $d$):**
$$M = C^d \mod n$$
-
Decryption Context in Pentesting:
-
Cracking weak encryption (short keys, poor RNG).
-
Analyzing captured encrypted traffic (if private key obtained or weak cipher used).
-
Testing for cryptographic flaws (padding oracle, weak ciphersuites).
-
-
Cryptography Audit Documentation - Key Elements:
-
Algorithms & Protocols Used (e.g., TLS 1.3, AES-256-GCM, RSA-2048).
-
Key Management Process (generation, storage, rotation, destruction).
-
Configuration Review (cipher suite order, certificate validity, HSTS policy).
-
Findings & Evidence (e.g., "SSLv2 enabled", "RSA key < 2048 bits").
-
5.0 POST-EXPLOITATION, REPORTING & COMMUNICATION
5.1 Documentation & Reporting
-
Standard Penetration Test Report Structure:
-
Executive Summary: High-level risks, business impact, budget implications (for management).
-
Scope & Methodology: What was tested, how, and tools used.
-
Technical Findings: Detailed vulnerabilities, proof-of-concept (PoC) code/screenshots, CVSS scores.
-
Remediation Recommendations: Specific, actionable steps (prioritized).
-
Conclusion & Overall Risk Rating.
-
-
Cryptography Audit Report Specifics:
-
Must include cryptographic inventory (all uses of crypto in the system).
-
Detailed algorithm and key length analysis against current standards (NIST, BSI).
-
Review of PKI infrastructure (CA, certificate chain, revocation).
-
5.2 Stakeholder Engagement
-
Importance for Success: Technical findings are useless if not understood or acted upon.
-
Communicating to Non-Technical Management:
-
Translate technical risk into business risk (e.g., "SQLi vulnerability → potential for full customer database theft → regulatory fines & reputational damage").
-
Use risk matrices (Likelihood vs. Impact).
-
Avoid jargon; focus on impact and cost.
-
-
Facilitating Remediation:
-
Collaborative Meetings: Walk developers/network teams through findings.
-
Prioritization: Help stakeholders understand which fixes are critical vs. low-effort wins.
-
Retesting: Schedule validation to ensure fixes are effective.
-
6.0 SPECIAL CONTEXTS & ADVANCED SCENARIOS
6.1 Case Study: https://www.rgpvonline.com (Educational Portal)
-
Primary Test Objectives:
-
Data Leakage: Student PII, grades, financial data exposure.
-
Authentication & Authorization: Bypassing login, privilege escalation (student → admin).
-
Information Disclosure: Error messages, server banners, source code leaks.
-
API Security: If mobile app/API exists, test for IDOR, excessive data exposure.
-
-
Likely Threat Model: Students (insider threat), external attackers seeking data, competitors.
6.2 Capture The Flag (CTF) Competitions
-
Simulation of Real-World Scenarios:
-
Time Pressure: Mimics incident response or limited engagement windows.
-
Diverse Skill Sets: Requires blending of recon, exploitation, forensics, crypto, web.
-
Unknown Environment: "Black-box" testing; no prior knowledge of systems.
-
Learning Outcome: Develops adaptive problem-solving and rapid research skills under pressure.
-
6.3 Cloud Security Penetration Testing
-
Unique Considerations:
-
Shared Responsibility Model: Pentester must know what the cloud provider secures (hypervisor, physical) vs. what the client secures (IAM, S3 buckets, app config).
-
API Security: Cloud is API-driven. Test for excessive permissions, insecure direct object references (IDOR) in cloud APIs (AWS, Azure).
-
Misconfiguration: #1 risk. Focus on:
-
S3 Buckets: Public read/write access.
-
IAM Policies: Overly permissive roles, unused keys.
-
Security Groups/NSGs: Open ports (0.0.0.0/0 on 22, 3389).
-
-
-
Cloud-Specific Tools:
ScoutSuite,Prowler(AWS),Azure Security Toolkit,CloudGoat(training).
[!TIP] Final Exam Strategy: For "Discuss" questions (7m), use point-wise structure: Definition → Key Features → Example/Tool → Impact/Risk → Mitigation. Always link back to real-world business impact.