Lecture 02: Phases and Frameworks CY461: Penetration Testing
CY461: PENETRATION TESTING
Dr. Rashid Jillani
✓ Phases
✓ Frameworks
Ghulam Ishaq Khan Institute of Engineering Sciences and Technology, Topi
Lecture 02: Phases and Frameworks CY461: Penetration Testing
Penetration Testing Types
• Blackbox Testing
• Whitebox Testing
• Graybox Testing
Ghulam Ishaq Khan Institute of Engineering Sciences and Technology, Topi
Lecture 02: Phases and Frameworks CY461: Penetration Testing
Penetration Testing Phases
• Pre-Engagement
• Intelligence Gathering
• Threat Modeling
• Vulnerability Analysis
• Exploitation
• Post Exploitation
• Reporting
Ghulam Ishaq Khan Institute of Engineering Sciences and Technology, Topi
Lecture 02: Phases and Frameworks CY461: Penetration Testing
Pre-Engagement
• Discussing the scope and terms of the penetration
test with your client
• Convey the goals of the penetration test
• Use this opportunity to discuss what will happen, the
expectations of a full scale penetration test
• What will be tested – the need for total access to get a
complete report
Ghulam Ishaq Khan Institute of Engineering Sciences and Technology, Topi
Lecture 02: Phases and Frameworks CY461: Penetration Testing
Intelligence Gathering
• Gather information about the organization (social media, Google
hacking, etc)
• Start to probe the organization for ports with blocking (use a
disposable IP address,
– you will be blocked if this is turned on)
- Test any Web Applications
Ghulam Ishaq Khan Institute of Engineering Sciences and Technology, Topi
Lecture 02: Phases and Frameworks CY461: Penetration Testing
Threat Modeling
• Using the information acquired in the intelligence gathering.
• Look at the organization as an adversary and determine
– where the threats are coming from,
– what form they may take
– and what they are after.
Ghulam Ishaq Khan Institute of Engineering Sciences and Technology, Topi
Lecture 02: Phases and Frameworks CY461: Penetration Testing
Vulnerability Analysis
• You will use all the previous information from prior phases.
• This is a detailed analysis taking into account port and
vulnerability scans, banner grabbing, and information from
intelligence gathering.
Ghulam Ishaq Khan Institute of Engineering Sciences and Technology, Topi
Lecture 02: Phases and Frameworks CY461: Penetration Testing
Exploitation
• The main part of the penetration test
• Often brute force instead of precision
• Separates the “good” and the “bad” testers –
– “Bad” testers will fire off massive onslaught of exploits
– “Good” testers will perform only exploits expected to succeed based
on info gathered
– Creating “noise” with massive exploits and hoping for a result is not
the way!
Ghulam Ishaq Khan Institute of Engineering Sciences and Technology, Topi
Lecture 02: Phases and Frameworks CY461: Penetration Testing
Post Exploitation
• After you have compromised one or more systems (there are
many more to come)
• Targets specific systems
• Identifies critical infrastructure
• Targets information or data of value to the company
• Start with systems that will present the most business impact to
the company if breached
Ghulam Ishaq Khan Institute of Engineering Sciences and Technology, Topi
Lecture 02: Phases and Frameworks CY461: Penetration Testing
Post Exploitation
• Take the time to determine what systems do and their different
user roles
• Ex: suppose you compromise a domain? Big deal.
• What else could you do in terms of the systems that the
business uses? Backdoor code on a financial application? What
about their payroll system? Intellectual property?
Ghulam Ishaq Khan Institute of Engineering Sciences and Technology, Topi
Lecture 02: Phases and Frameworks CY461: Penetration Testing
Reporting
• Most important element of the penetration test
• Include at least:
▪ Executive Summary
▪ Executive Presentation
▪ Technical Findings
• Used by the client to remediate security holes
• Be sure to warn the client about the thinking that fixing the hole solves the
whole problem. Ex: sql injection vulnerability – they fix their problem, but
have they addressed any 3rd party applications that are connected?
Ghulam Ishaq Khan Institute of Engineering Sciences and Technology, Topi
Lecture 02: Phases and Frameworks CY461: Penetration Testing
Penetration Testing Phases
Ghulam Ishaq Khan Institute of Engineering Sciences and Technology, Topi
Lecture 02: Phases and Frameworks CY461: Penetration Testing
Types of Penetration Tests
• Overt Penetration Testing
– You work with the organization to identify the potential security threats
• Advantages: full access without blocks, detection doesn’t
matter, access to insider knowledge
• Disadvantages: don’t get the opportunity to test incident
response
• Covert Penetration Testing
– Performed to test the internal security team’s ability to detect and respond to
an attack
• Advantages: Test incident response, most closely simulates a
true attack
• Disadvantages: Costly, time consuming, require more skill
• Note: because of cost of covert – most will target only one
vulnerability, the one with easiest access – gaining access
undetected is key
Ghulam Ishaq Khan Institute of Engineering Sciences and Technology, Topi
Lecture 02: Phases and Frameworks CY461: Penetration Testing
Vulnerability Scanners
• Automated tools used to identify security flaws
– 1. Fingerprint a target’s operating system
– 2. Take one OS identified, use scanner to determine if vulnerabilities exist
– Although Vulnerability Scanners play an essential role in Penetration
Testing, a penetration test CANNOT be completed automated! Most
penetration testers with years of experience rarely use vulnerability
scanners – they rely more on their knowledge and experience – business
knowledge is also a key factor.
Ghulam Ishaq Khan Institute of Engineering Sciences and Technology, Topi
Lecture 02: Phases and Frameworks CY461: Penetration Testing
Threat Actors
• Organized Crime
• Hacktivists
• State-Sponsored Attackers
• Insider Threats
Ghulam Ishaq Khan Institute of Engineering Sciences and Technology, Topi
Lecture 02: Phases and Frameworks CY461: Penetration Testing
Penetration Testing Methodologies
• Systemic and organized approach
• Well-known methods and standards
• Documentation provides accountability
• Scope creep
• Tried and tested
Ghulam Ishaq Khan Institute of Engineering Sciences and Technology, Topi
Lecture 02: Phases and Frameworks CY461: Penetration Testing
Environmental Considerations
• Network Infrastructure Tests
– Switches, routers, firewalls, and supporting resources, such as AAA servers and
IPSs.
– Wireless infrastructure may be included
• Application-Based Tests
– Enterprise applications
– Misconfigurations, input validation issues, injection issues, and logic flaws
– Web server, database
• Penetration Testing in the Cloud
– Cloud model (SaaS, PaaS, or IaaS)
– Disaster recovery, SLAs, data integrity, and encryption
• Social Engineering ???
Ghulam Ishaq Khan Institute of Engineering Sciences and Technology, Topi
Lecture 02: Phases and Frameworks CY461: Penetration Testing
Environmental Considerations (Perspective)
• Unknown-Environment Test
– Black-box
• Known-Environment Test
– White-box
• Partially Known Environment Test
– Gray-box
Ghulam Ishaq Khan Institute of Engineering Sciences and Technology, Topi
Lecture 02: Phases and Frameworks CY461: Penetration Testing
Penetration Testing Methodologies
• MITRE ATT&CK
– Enterprise ATT&CK Matrix, Network, Cloud, ICS, and Mobile
• OWASP Web Security Testing Guide (WSTG)
– High-level phases of web application security testing
– Provides attack vectors for testing cross-site scripting (XSS), XML external entity
(XXE) attacks, cross-site request forgery (CSRF), and SQL injection attacks
– how to prevent and mitigate these attacks
• NIST SP 800-115
– Industry standard for penetration testing
– Provides guidelines on planning and conducting information security testing
Ghulam Ishaq Khan Institute of Engineering Sciences and Technology, Topi
Lecture 02: Phases and Frameworks CY461: Penetration Testing
Penetration Testing Methodologies (Contd…)
• OSSTMM (Open Source Security Testing Methodology Manual)
– Operational Security Metrics, Trust Analysis, Work Flow, Human Security
Testing, Physical Security Testing, Wireless Security Testing, Telecommunications
Security Testing, Data Networks Security Testing, Compliance Regulations,
and Reporting with the Security Test Audit Report (STAR).
• PTES (Penetration Testing Execution Standard)
– Seven distinct phases: Pre-engagement interactions, Intelligence gathering, Threat
modeling, Vulnerability analysis, Exploitation, Post-exploitation, and Reporting
• ISSAF (Information Systems Security Assessment Framework)
– Information gathering, Network mapping, Vulnerability identification,
Penetration, Gaining access and privilege escalation, Enumerating
further, Compromising remote users/sites, Maintaining access, and Covering the
tracks
Ghulam Ishaq Khan Institute of Engineering Sciences and Technology, Topi
Lecture 02: Phases and Frameworks CY461: Penetration Testing
Penetration Testing Methodologies (Contd…)
• Cobalt Strike Framework
– Set of threat emulation tools
– Simulate network intrusions
– Creates a communication channel between attack tools and the
compromised system, providing more in-depth insights.
• Metasploit Framework
– Database that contains a large number of known vulnerabilities and
exploits, a payload generator, and other tools.
Ghulam Ishaq Khan Institute of Engineering Sciences and Technology, Topi