UNIT 5: Penetration Testing and Vulnerability Analysis
I. Foundations and Pre-Engagement
A. Legal and Ethical Considerations
-
Impact on Organizational Decision-Making:
-
Authorization: Formal, written consent (Get Out of Jail Free card) is mandatory. Unauthorized testing is illegal (Computer Fraud and Abuse Act, IT Act 2000).
-
Compliance: Tests must align with regulations (GDPR, HIPAA, PCI-DSS) to avoid fines and liability.
-
Liability: Defines scope to prevent damage to production systems/data. Clauses for "damage control" and indemnification are critical.
-
Ethical Frameworks: Guides behavior (e.g., (ISC)² Code of Ethics, EC-Council Code). Emphasizes do no harm, confidentiality, and professionalism.
-
-
[!TIP] Exam Focus: Always link legal/ethical points to organizational risk (financial, reputational, legal). Mention specific acts/laws.
B. Stakeholder Engagement
-
Role in Security Implementation:
-
Aligns Expectations: Prevents "scope creep" and ensures business goals (e.g., "test customer portal only") are met.
-
Facilitates Communication: Regular updates to management (high-level risks) vs. technical teams (vulnerability details).
-
Manages Business Impact: Coordinates testing windows to avoid downtime.
-
-
[!TIP] Common Pitfall: Poor stakeholder communication leads to mistrust, ignored reports, and failed security investments.
C. Objectives, Scope, and Rules of Engagement (ROE)
-
Defining Boundaries:
-
In-Scope: IP ranges, applications (e.g.,
https://app.rgpvonline.com), cloud assets, specific testing types (black-box, white-box). -
Out-of-Scope: Production databases, third-party services, DDoS testing.
-
ROE: "What, When, How." Includes allowed tools/techniques, data handling procedures, and emergency contacts.
-
-
Success Criteria: Measurable goals (e.g., "Identify all critical CVEs," "Achieve domain admin access").
II. Reconnaissance and Information Gathering
A. DNS Reconnaissance
-
Purpose: Map the target's digital footprint, identify hosts, subdomains, and network topology.
-
Techniques & Tools:
-
Zone Transfer (AXFR):
dig @ns1.rgpvonline.com rgpvonline.com axfr -
Enumeration:
nslookup,host,dnsrecon,Sublist3r,Amass. -
Brute-Force: Wordlist-based subdomain discovery.
-
-
Crucial Output: List of subdomains → attack surface expansion.
B. External Presence Assessment (OSINT)
-
Criticality: The external footprint is the attacker's starting point. Information leakage (employee names, tech stack, emails) enables targeted attacks (phishing, credential stuffing).
-
OSINT Techniques:
-
Search Engines: Google Dorks (
site:rgpvonline.com filetype:pdf). -
Social Media: LinkedIn (employee roles), GitHub (code leaks,
.gitdirectories). -
Public Records: WHOIS, DNS history (SecurityTrails), certificate transparency logs (crt.sh).
-
C. Target System Architecture Analysis
-
Importance Pre-Exploitation: Understanding architecture prevents wasted effort and unintended damage.
-
Network Topology: Firewalls, segmentation, DMZ.
-
Application Stack: OS, web server (Apache/Nginx), framework (Django/Spring), database (MySQL/PostgreSQL).
-
Dependencies: Third-party libraries, APIs, cloud services (AWS S3, Azure AD).
-
-
Output: A network diagram and technology stack profile guide exploit selection.
III. Penetration Testing Domains and Methodologies
A. Network Penetration Testing
-
Use Cases: External perimeter assessment, internal lateral movement, firewall rule bypass.
-
Scope: IP ranges, network devices (routers, switches), services (SSH, RDP, SMB).
-
Common Attack Vectors:
-
Recon:
nmap -sS -sV -O 10.0.0.0/24 -
Exploitation: SMB exploits (EternalBlue), credential brute-forcing, MITM attacks.
-
Post-Exploitation: Pivoting, credential dumping (Mimikatz), persistence.
-
B. Application Penetration Testing
-
vs. Network Testing: Focuses on application logic, data handling, and business flows, not just open ports.
-
Scope: Specific applications (web, mobile, API), user roles (admin, user).
-
Focus: Business Logic Flaws (e.g., price manipulation, IDOR), session management, input validation.
C. Web Application Penetration Testing Methodologies
-
Structured Approaches:
-
OWASP Testing Guide: Standard, comprehensive checklist (v4.2).
-
PTES (Penetration Testing Execution Standard): Phases: Pre-engagement, Intelligence Gathering, Threat Modeling, Vulnerability Analysis, Exploitation, Post-Exploitation, Reporting.
-
-
Core Phases:
-
Recon: Spidering, content discovery.
-
Discovery: Automated scanning (Burp Suite), manual testing for Vulns.
-
Exploitation: Proof-of-Concept (PoC) development.
-
Reporting: Detailed findings with risk ratings.
-
D. Cloud Security Testing
-
Unique Challenges: Dynamic environments (auto-scaling), API-driven, shared responsibility model.
-
Shared Responsibility: Provider secures the cloud (infrastructure); Customer secures in the cloud (configs, data, IAM).
-
Misconfiguration Testing:
-
IaaS (EC2): Open security groups, exposed S3 buckets.
-
PaaS (Elastic Beanstalk): Overly permissive IAM roles.
-
SaaS (Office 365): Weak MFA policies, excessive admin privileges.
-
-
Tools:
ScoutSuite,Prowler,CloudGoat(for hands-on).
IV. Vulnerability Analysis and Exploitation Techniques
A. Web Application Vulnerabilities
1. HTTP Strict Transport Security (HSTS)
-
Purpose: Enforces HTTPS-only connections, preventing SSL Stripping attacks.
-
Mechanism: Server sends header
Strict-Transport-Security: max-age=31536000; includeSubDomains; preload. -
Risks of Improper Implementation:
-
No
max-ageor short duration → ineffective. -
Missing
includeSubDomains→ subdomains vulnerable. -
Preload List: Submission to Chrome/Firefox preload list for strict enforcement even on first visit.
-
2. SQL Injection (SQLi)
-
Primary Risk: Unauthorized Data Access, Modification, or Deletion. Can lead to full database compromise, authentication bypass, or remote code execution (in some DBs).
-
Detection Techniques:
-
Error-Based: Trigger DB errors (
' OR 1=1--). -
Boolean-Based: Compare true/false responses (
' AND 1=1--vs' AND 1=2--). -
Time-Based:
' AND SLEEP(5)--(delay response). -
UNION-Based: Extract data from other tables (
UNION SELECT null, username, password FROM users--).
-
-
Exploitation: Data exfiltration, dropping tables, file system access (MySQL
INTO OUTFILE).
B. Wireless Network Vulnerabilities
1. Packet Sniffing in Wireless Testing
-
Importance: Wireless traffic is broadcast by nature. Sniffing captures:
-
Unencrypted protocols (HTTP, FTP, Telnet).
-
Handshake for WPA/WPA2 cracking.
-
Management frames for rogue AP detection.
-
-
Tools & Techniques:
-
Wireshark: Protocol analysis, filtering (
wlan.fc.type_subtype == 0x08for beacons). -
aircrack-ng suite:
airodump-ngto capture handshakes,aircrack-ngto crack PSK. -
Mode: Put NIC in monitor mode (
iwconfig wlan0 mode monitor).
-
C. Social Engineering
1. Tactics Targeting Wireless Networks
-
Rogue Access Point (Evil Twin): Mimics legitimate SSID to lure users.
-
Wi-Fi Phishing: "Captive Portal" mimicking hotel/login page to harvest credentials.
-
Physical Tailgating: Gaining physical access to deploy malicious devices.
2. Mitigation through Employee Training
-
How Training Reduces Risk: Builds a human firewall by teaching recognition of phishing, suspicious Wi-Fi, and social manipulation.
-
Key Components of Effective Program:
-
Regular Phishing Simulations: Controlled tests with follow-up training.
-
Clear Reporting Channels: Easy way to report suspicious activity.
-
Role-Based Training: Tailored to user roles (finance, IT).
-
Continuous Reinforcement: Not a one-time event.
-
D. Cryptography in Security Testing
1. RSA Algorithm for Secure Communication
-
Demonstration (Key Generation & Use):
-
Key Gen:
-
Choose primes $p, q$.
-
Compute $$\displaystyle n = p \times q $$, $$\displaystyle \phi(n) = (p-1)(q-1) $$.
-
Choose $e$ where $$\displaystyle 1 < e < \phi(n) $$, $$\displaystyle \gcd(e, \phi(n)) = 1 $$ (often 65537).
-
Compute $$\displaystyle d \equiv e^{-1} \mod \phi(n) $$.
-
Public Key: $(e, n)$; Private Key: $(d, n)$.
-
-
Encryption (by sender): $$\displaystyle c \equiv m^e \mod n $$
-
Decryption (by receiver): $$\displaystyle m \equiv c^d \mod n $$
-
Digital Signature (by sender): $$\displaystyle s \equiv m^d \mod n $$; Verify: $$\displaystyle m' \equiv s^e \mod n $$
-
-
Strengths: Asymmetric, enables secure key exchange (TLS), digital signatures.
-
Weaknesses in Implementation:
-
Small key sizes (512-bit) → factorable.
-
Poor random number generation → key predictability.
-
Side-channel attacks (timing, power analysis).
-
2. Decryption Techniques (Pentesting Context)
-
Cracking Weak Encryption: WEP/WPA-PSK (using aircrack-ng), weak SSL ciphers.
-
Analyzing Captured Data: Decrypting SSL/TLS traffic with server private key (
sslkeylogfile). -
Brute-Forcing: Password-protected files (ZIP, PDF) using
John the Ripper,Hashcat. -
Cryptanalysis: Identifying flawed implementations (e.g., ECB mode, predictable IVs).
3. Cryptography Audit Documentation
-
Key Elements in Report:
-
Algorithms & Key Lengths: AES-256, RSA-2048, SHA-256.
-
Key Management: Storage (HSM?), rotation policies, access controls.
-
Protocol Implementation: TLS version, cipher suite strength, certificate validity.
-
Findings: Weak ciphers, expired certs, hard-coded keys.
-
Recommendations: Upgrade protocols, implement key rotation, use HSM.
-
V. Tools, Simulations, and Practical Application
A. Vulnerability Scanning Tools
-
Categories & Examples:
-
Network:
Nmap(port scan, service detection),Nessus/OpenVAS(comprehensive vuln scanning). -
Web Application:
Burp Suite(proxy, scanner),OWASP ZAP(open-source). -
Configuration:
Nikto(web server),Lynis(Linux hardening).
-
-
Role: Automated discovery of known vulnerabilities (CVEs), misconfigurations.
-
Limitations:
-
False Positives/Negatives: Requires manual verification.
-
No Business Logic Flaws: Cannot understand application context.
-
Rate Limiting: Can trigger IDS/IPS.
-
B. Capture The Flag (CTF) Competitions
-
Simulation of Real-World Scenarios:
-
Jeopardy-style: Challenges in categories (Web, Crypto, Pwn, Forensics, OSINT).
-
Attack-Defense: Teams defend their own services while attacking others.
-
-
Value in Skill Development:
-
Hands-On Practice: Exploiting real vulnerabilities in isolated environments.
-
Time Pressure: Mimics real engagement constraints.
-
Learning New Techniques: Exposure to obscure vulns and tools.
-
C. Case Study Analysis and Reporting: https://www.rgpvonline.com
-
Applying Methodologies:
-
Recon: OSINT on rgpvonline.com, DNS enumeration.
-
Discovery: Web app scanning (Burp), network scanning (Nmap).
-
Exploitation: Test for SQLi, XSS, CSRF, authentication bypass.
-
Post-Exploitation: If compromised, pivot, escalate privileges.
-
-
Structuring Findings & Recommendations:
-
Executive Summary: High-level risks for management.
-
Methodology: Steps taken (PTES/OWASP).
-
Vulnerabilities: Each with Proof-of-Concept (PoC), impact, CVSS score, remediation steps.
-
Recommendations: Prioritized (Critical/High/Medium/Low), actionable fixes.
-
Conclusion: Overall security posture assessment.
-
[!TIP] Exam Strategy: For case study questions, outline the methodology steps first, then apply to the given domain (e.g., "For rgpvonline.com, I would first perform DNS recon using
sublist3r...").