Showing posts with label Penetration Testing. Show all posts
Showing posts with label Penetration Testing. Show all posts

Tuesday, 6 October 2015

PHASES OF A PENETRATION TESTING

Like most things, the overall process of penetration testing can be broken down into a series of steps or phases. When put together, these steps form a comprehensive methodology for completing a penetration test. Careful review of unclassified incident response reports or breech disclosures supports the idea that most black hat hackers also follow a process when attacking a target. The use of an organized approach is important because it not only keeps the penetration tester focused and moving forward but also allows the results or output from each step to be used in the ensuing steps. The use of a methodology allows you to break down a complex process into a series of smaller more manageable tasks. Understanding and following a methodology is an important step in mastering the basics of hacking. Depending on the class you are taking, this methodology usually contains between four and seven steps or phases. Although the overall names or number of steps can vary between methodologies, the important thing is that the process provides a complete overview of the penetration testing process.

For example, some methodologies use the term “Information Gathering,” whereas others call the same process “Reconnaissance.” I will focus on the activities of the phase rather than the name. I will use a four-step process to explore and learn penetration testing. If you search around and examine other methodologies (which is important to do), you may find processes that include more or less steps than I am using as well as different names for each of the phases. It is important to understand that although the specific terminology may differ, most solid penetration testing methodologies cover the same topics. There is one exception to this rule: the final step in many hacking methodologies is a phase called “hiding,” “covering your tracks,” or “removing evidence.” So it will not be included in the coming post. Once you have a solid understanding of the basics, you can go on to explore and learn more about this phase. For the time being I am just refreshing the four simple steps: Reconnaissance, Scanning, Exploitation, and Maintaining Access. Sometimes, it helps to visualize these steps as an inverted triangle.


The reason I use an inverted triangle is because the outcome of initial phases is very broad. As we move down into each phase, we continue to drill down to very specific details. The inverted triangle works well because it represents our journey from the broad to the specific. For example, as we work through the reconnaissance phase, it is important to cast our nets as wide as possible. Every detail and every piece of information about our target is collected and stored. The penetration testing world is full of many great examples when a seemingly trivial piece of information was collected in the initial phase and later turned out to be a crucial component for successfully completing an exploit and gaining access to the system. In later phases, we begin to drill down and focus on more specific details of the target. Where is the target located? What is the IP address? What operating system is the target running? What services and versions of software are running on the system? As you can see, each of these questions becomes increasingly more detailed and granular. It is also important to understand the order of each step. The order in which we conduct the steps is very important because the result or output of one step needs to be used in the step below it. You need to understand more than just how to simply run the security tools from the future post. Understanding the proper sequence in which they are run is vital to performing a comprehensive and realistic penetration test. For example, many newcomers skip the Reconnaissance phase and go straight to exploiting their target. Not completing steps 1 and 2 will leave you with a significantly smaller target list and attack vector on each target. In other words, you become a one-trick-pony. Although knowing how to use a single tool might be impressive to your friends, it is not to the security community and professionals who take their job seriously. It may also be helpful for newcomers to think of the steps we will cover as a circle. It is very rare to find critical systems exposed directly to the Internet in today’s world. In many cases, penetration testers must access and penetrate a series of related targets before they have a path to reach the original target. In these cases, each of the steps is often repeated.

Zero Entry Hacking: A Four-Step Model


Let us briefly review each of the four steps that will be covered so you have a solid understanding of them. The first step in any penetration test is “reconnaissance.” This phase deals with information gathering about the target. As was mentioned previously, the more information you collect on your target, the more likely you are to succeed in later steps. Reconnaissance will be discussed in detail in coming posts. Regardless of the information you had to begin with, after completing in-depth reconnaissance you should have a list of target IP addresses that can be scanned. The second step in our methodology can be broken out into two distinct activities. The first activity we conduct is port scanning. Once we have finished with port scanning, we will have a list of open ports and potential service running on each of the targets. The second activity in the scanning phase is vulnerability scanning. Vulnerability scanning is the process of locating and identifying specific weaknesses in the software and services of our targets. With the results from Scanning, we continue to the “exploitation” phase. Once we know exactly what ports are open, what services are running on those ports, and what vulnerabilities are associated with those services, we can begin to attack our target. This is the phase that most newcomers associate with “real” hacking. Exploitation can involve lots of different techniques, tools, and code. We will review a few of the most common tools in coming posts. The ultimate goal of exploitation is to have administrative access (complete control) over the target machine. The final phase we will examine is “maintaining access.” Often-times, the payloads delivered in the exploitation phase provide us with only temporary access to the system. Because most payloads are not persistent, we need to create a more permanent backdoor to the system. This process allows our administrative access to survive program closures and even reboots. we must be very careful about the use and implementation of this phase. We will discuss how to complete this step as well as the ethical implications of using backdoor or remote control software. Although not included as a formal step in the penetration testing methodology, the final (and arguably the most important) activity of every Penetration Testing is the report. Regardless of the amount of time and planning you put into conducting the penetration test, the client will often judge your work and effectiveness on the basis of the quality of your report. The final Penetration Testing report should include all the relevant information uncovered in your test and explain in detail how the test was conducted and what was done during the test. Whenever possible, mitigations and solutions should be presented for the security issues you uncovered. Finally, an executive summary should be included in every Penetration Testing report. The purpose of this summary is to provide a simple one- to two-page, non-technical overview of your findings. This report should highlight and briefly summarize the most critical issues your test uncovered. It is vital that this report be readable (and comprehensible) by both technical and non-technical personnel. It is important not to fill the executive summary with too many technical details that is the purpose of the detailed report.

Types of Penetration Testing

Automated vs. Manual
Automated and manual penetration testing can be both used as a means to evaluate an organization’s security controls system. Automated testing has been the mainstream approach adopted by organizations because of the rapid technological changes to provide economies of scale compared to manual one. A thorough manual testing may consist of several weeks with an investment of thousands of dollars, whereas an automated can perform the tests within several hours with reduced costs. This shows that automated tools can be more cost-effective and efficient if conducted properly. Another benefit of automation is that organizations can perform these tests as frequent as they want compared to ethical hacking practitioners who conduct testing only during working hours.
On the other hand, there can be an overreliance and false sense of security on automated tools because they do not guarantee that it will catch 100% of the security gaps in the system and are only as effective as the individuals who programmed and run these tests. In other words, there is a risk that an untrained employee who handles and manages the automated testing can cause more damages to the organization than the expected benefit. Furthermore, an automated testing lacks the flexibility of substituting different scenarios as compared to an extensive manual testing performed by a knowledgeable and experienced ethical hacking practitioner.
An example of a company who performs automated penetration testing is iViz, the first cloud-based penetration testing that provides high quality of services for applications with “on-demand SaaS experience”. The benefits include the use of artificial intelligence to simulate all types of intrusion attacks, a zero false positive with the aid of “business logic testing and expert validation”, the flexibility to conduct a penetration test at any time, no required software or hardware, the scalability and the cost- subscription model. In comparison of Sales-force to customer relationship management, iViz has performed the same transformation to penetration testing.
External vs. Internal
As identified above, testing should be conducted to address the internal and external threats. Internal testing is performed within the organization’s system and simulates what an authorized user or employee could potentially act. On the other hand, external testing attempts to simulate what an external hacker could potentially harm from outside the system. The red team would conduct intrusion attacks on the organization’s network system through the use of the Internet or Extranet25. The red team generally targets the organization’s servers or devices, such as “Domain Name Server, email server, web server or firewalls”. It appears that an internal testing may be more comprehensive because an authorized user can either use the internal or external system to hack into an organization’s information system.
Blind vs. Double-Blind vs. Targeted Testing
In a blind testing environment, the red team is only provided with publicly available information, such as the organization’s website, domain name registry and any other related discussion boards on the Internet. With this limited information, penetration testing attempts to accumulate information to exploit an organization’s security weaknesses. It can reveal information about an organization that it would not have known, but can be more time-consuming and expensive due to the extensive effort to conduct research prior to the testing phase.
In a double-blind testing environment, the blind testing process is expanded in which the organization’s IT and other staffs are not informed beforehand about the intended testing activities. Hence, they are also considered “blind” to the test. In this type of scenario, very limited people within the organization are aware of the testing, and it requires continuous monitoring by the project sponsor to ensure that the testing procedures can be eliminated once the objective has been attained. Furthermore, this test can reveal the effectiveness of an organization’s monitoring, identification and response procedures to incidents.
In a targeted testing environment, the organization’s IT and other staffs are notified about the testing activities beforehand and the penetration testers are provided with network design layout and other related information. This type of scenario may be more efficient and cost-effective because it tends to be less time-consuming than both the blind and double-blind testing. However, it may not offer a “complete picture of an organization’s security vulnerabilities and response capabilities”.

Penetration Testing: An IT Organization Must Do!

I. Introduction
Due to the increasing vulnerability to hacking in today’s changing security environment, the protection of an organization’s Information Security Management System (ISMS) has become a business imperative. With the access to the Internet by anyone, anywhere and anytime, the Internet’s ubiquitous presence and global accessibility can become an organization’s weakness because its security controls can become more easily compromised by internal and external threats. Hence, the purpose of this article is to strengthen the awareness of ethical hacking in the IT Organization, also known as penetration testing, by evaluating the effectiveness and efficiency of the ISMS.
II. What is Ethical Hacking/Penetration Testing?
Ethical hacking and penetration testing is a preventative measure which consists of a chain of legitimate tools that identify and exploit a company’s security weaknesses. It uses the same or similar techniques of malicious hackers to attack key vulnerabilities in the company’s security system, which then can be mitigated and closed. In other words, penetration testing can be described as not “tapping the door”, but “breaking through the door”. These tests reveal how easy an organization’s security controls can be penetrated, and to obtain access to its confidential and sensitive information asset by hackers. As a result, ethical hacking is an effective tool that can help assist IT professionals to better understand the organization’s information systems and its strategy, as well as to enhance the level of assurance and IS audits if used properly.
III. Basic Characteristics of Penetration Testing
Different Types of “Hat Hackers”
There are different types of “hat hackers” that should be distinguished: black, grey, and white. “Black hat hackers” perform unauthorized penetration attacks against information systems, which may or may not be illegal in the country they are conducting. On the other hand, ethical hackers are known as “white hat hackers” because they legitimately perform security tests bounded by a contractual agreement. Their main purpose is to improve the system which can then be closed before a real criminal hacker penetrates within the organization. “Grey hat hackers” are those in-between the black and white that perform their activities within legal legislations and regulations but may slightly go over the boundaries. Since penetration testing is an authorized attempt to intrude into an organization’s network, the focus of the paper will be on the “white hat hackers”.
IV. Threats/Risks Relevant to Organizations
In order to conduct a penetration testing, threats and risks should first be identified and analyzed because this forms the basis of the test in which ethical hackers would attempt to attack an organization’s system to expose those vulnerabilities. In the same manner, IT practitioners should be fully aware of the information security risks that are relevant to any organization because it can adversely affect their business operations and cause their security systems vulnerable to unauthorized access, increasing both business and information risks respectively. In the following, two major risks will be discussed – internal and external.
a.  Internal Threat/Risks
Regardless of how strong a computer security system is designed, employees’ lack of knowledge about security issues and other malicious employees can inflict enormous damages to any organization. With limited employee security awareness, simple actions of opening a “joke email”, which may be infected with a virus, can place the organization at risk with thousands of lost revenue. Key statistics from a medium-size company case study have indicated that 100% of all employees use instant messaging, which should have been prevented by the corporate firewalls, and 40 out of 100 users use common dictionary words as legitimate and valid passwords which can be easily guessed by other employees for unauthorized access. In addition, less than 25% of the employees have used an external device to copy files off-site and 33% have transmitted confidential documents to a laptop. Employees also run the chance of using cloud services, such as Google Docs or Dropbox, for the convenience of transferring corporate data, and this bypasses the IT department for proper procedures and policies. As a result, companies are now exposed in ways that the cloud can compromise its sensitive and confidential information, increasing the risk of rogue IT. This ultimately demonstrates that employees who are key personnel to running an organization successfully may also be the greatest weakness at the same time due to the unprotected exposure of unauthorized access.
b.   External Threat/Risks
External threats include a wide range of activities that are performed by real criminal hackers. By identifying the security gaps in an organization’s system, external hackers can exploit the system and gain authorized access to copy or delete sensitive information, such as customer’s credit card information.
In any security system, “information is crown”. This essentially means that whenever an organization’s information asset is compromised, this is a security issue which may be caused by technical issues, human errors or processing weaknesses. As a result, both internal and external threats must be identified and proactively addressed by organizations because it can bring financial and non-financial losses, including lawsuits related to release of confidential, private, commercial or other highly-sensitive information, lost in revenue, damaged reputation, loss of credibility in the eyes of customers and loss of control in computer system.
VI. Penetration Testing Techniques
There are various technical and non-technical techniques that can be utilized as part of the penetration testing process to address the internal and external threats. The following is a list of the most common tools used in a penetration test:
1.   Web Applications Software: Since many organizations sell many business applications over the Internet, testing can consist of evaluating the level of encryption used for processing confidential and sensitive information (128 or 256-bits), firewalls, the use of cookies stored on their customers’ computers31, the length and strength of passwords (upper and lower cases with numbers/letters) and the security of software configurations. For instance, a message should not plainly indicate that there was an incorrect password only, and no problem with the login username.
2.    Denial of Service: This testing depends on the organization’s commitment of having continuous availability of the information system. The red team evaluates the system’s vulnerability to attacks that will either cause the system to deny service from legitimate access, or to become totally unavailable due the inability to handle high volume of traffic, such as instantly sending millions of spam messages to the organization’s mail server.
3.   War Dialing: This testing consists of systematically calling numerous telephone numbers in order to identify “modems, remote access devices and maintenance connections” that are present in an organization’s network. Once identified, exploitation techniques, such as strategic attempts to guess the username and password, are performed to assess whether the connection can be used as a way to penetrate into its information security system.
4.    Wireless Network: Penetration testers will drive or walk around the office buildings to identify opened wireless networks of the organization that should have not been present in the first place. The purpose is to identify security gaps or errors in the “design, implementation and operation” of a company’s wireless network system.
5.    Social Engineering: Penetration testers would attempt to deceive the organization’s employees and suppliers in order to gather sensitive information and penetrate into an organization’s systems, such as claiming to be an IT representative and asking for the users’ login and passwords. Even though this is a non-technical testing which involves human-related features, it is viewed as equally important to determine whether unauthorized users can gain access to the information system.
6.    Google Hacking: Since Google is the one of the most common search engines widely used by organizations, penetration testers should consider Google hacking as an effective web security practice. It uses the search engine to locate personal or sensitive information by taking advantage of Google’s function of optimizing the search results anywhere in the websites. For instance, tests have found a directory with the social insurance number of more than 70 million deceased persons, and passport documents.
VII. Benefits of Penetration Testing
Penetration testing can help close the gap between safeguarding of an organization’s security system and the exposure of its security risks by assessing whether the security controls are adequate and working effectively.
As IT attacks are always changing in “nature, complexity and method”, penetration testing can be viewed as a solution to the evolving security threat environment and assist the organization’s IT system to stay constantly attentive and updated as part of the its overall security strategy. According to PCI and ISO 27001, managing security risks and threats is an essential management and IT process. The rationale behind this is that organizations should fully understand their weaknesses before they can effectively defend and protect themselves from unauthorized access. Hence, penetration testing can become a “hacker’s-eye” of any organization’s security system. Instead of possessing the wrong attitude towards security in hopes of not being hacked, organizations should take the appropriate actions to mitigate and control risk. Penetration testing can strengthen an organization’s security procedures and processes, as well as further improve the efficiency and effectiveness of its risk management. It can also consist of increasing the degree of transparency by assessing the type of sensitive data that can be potentially exposed, and how the network can be compromised by human elements. Ultimately, the main benefit is that organizations can learn from the penetration testing experience and further improve its security systems by thoroughly analyzing its weaknesses, properly implementing the changes, and informing all parties in a timely manner.
VIII. Limitations of Penetration Testing
Penetration testing cannot be expected to identify all possible security weaknesses, nor does it guarantee that it is 100% secure. New technology and hacking methods can create new exposures not anticipated during the penetration testing. Thus, it is certainly possible that after a penetration testing, there could be hacking incidents thereafter because it is impossible to have full but rather only good protection for an organization’s security system.
In addition, a penetration testing is usually performed within limited resources over a specific period of time. Therefore, once an ethical hacker has identified the current risk and threats exposed to the system, the organization should immediately take corrective action to mitigate these security loopholes and decrease the potential exposure to malicious hackers.
XIV: Conclusion
Penetration testing is an important component of an organization’s overall security strategy and can definitely add value if there are major security weaknesses in its system controls, and a high risk of unauthorized access due to the nature and operations of the business. Through controlled attempts to intrude into computer’s network system, a combination of penetration testing techniques and strategies can be developed to fit an organization’s needs in terms of nature of business, size and complexity of its operations. This will in turn enhance the assurance provided from auditors in assessing a company’s internal controls and security system at the same time. On the whole, ethical hacking and penetration testing should be considered as an efficient and effective means to mitigate and close security gaps and deficiencies before malicious hackers can otherwise exploit them.