Penetration Testing – The Process
Here’s a detailed description of the process involved in penetration testing:
Secure Permission
Don’t do anything on your target until you have written permission from your client. This
document can protect you from nasty lawsuits or similar problems. Verbal authorization is
not sufficient when performing hacking attacks. Remember: countries are implementing
strict rules and penalties regarding activities related to hacking.
Formulate a Plan
A plan can boost your chances of succeeding. Hacking a system can be extremely
complicated, especially when you are dealing with modern or unfamiliar systems. The last
thing you want to do is launch an attack with unorganized thoughts and tricks.
When creating a plan, you should:
Specify your target/s
Determine the risks
Determine the schedule and deadline of your penetration test
Specify the methods that you’ll use
Identify the information and access that you will have at the start of your test
Specify the “deliverables” (the output that you’ll submit to your client)
Focus on targets that are vulnerable or important. Once you have tested the
“heavyweights”, the remaining part of the test will be quick and easy.
Here are some targets that you can attack:
Mobile devices (e.g. smartphones)
Operating Systems
Firewalls
Email servers
Network Infrastructure
Workstations
Computer programs (e.g. email clients)
Here’s a detailed description of the process involved in penetration testing:
Secure Permission
Don’t do anything on your target until you have written permission from your client. This
document can protect you from nasty lawsuits or similar problems. Verbal authorization is
not sufficient when performing hacking attacks. Remember: countries are implementing
strict rules and penalties regarding activities related to hacking.
Formulate a Plan
A plan can boost your chances of succeeding. Hacking a system can be extremely
complicated, especially when you are dealing with modern or unfamiliar systems. The last
thing you want to do is launch an attack with unorganized thoughts and tricks.
When creating a plan, you should:
Specify your target/s
Determine the risks
Determine the schedule and deadline of your penetration test
Specify the methods that you’ll use
Identify the information and access that you will have at the start of your test
Specify the “deliverables” (the output that you’ll submit to your client)
Focus on targets that are vulnerable or important. Once you have tested the
“heavyweights”, the remaining part of the test will be quick and easy.
Here are some targets that you can attack:
Mobile devices (e.g. smartphones)
Operating Systems
Firewalls
Email servers
Network Infrastructure
Workstations
Computer programs (e.g. email clients)
