Manual and Automated Tests
Penetration testers divide tests into two categories: manual and automated. Manual tests
rely on the skills of a white hat hacker. The tester has complete control over the process. If
he makes a mistake, the entire penetration test can prove to be useless. Automated tests,
on the other hand, don’t need human intervention. Once the test runs, the computer will
take care of everything: from selecting targets to recording the results.
In this part of the book, you’ll learn important information regarding these types of tests.
You need to master this concept if you’re serious about hacking. With this knowledge, you
can easily determine the type of test that must be used in any situation.
Manual Penetration Tests
You will run manual tests most of the time. Here, you will use your tools, skills, and
knowledge to find the weaknesses of a network.
Manual tests involve the following steps:
Research – This step has a huge influence over the entire process. If you have a lot
of information about your target, attacking it will be easy. You can conduct research
using the internet. For example, you may look for specific information manually or
run your hacking tools.
Kali Linux has a wide of range of tools that you can use in this “reconnaissance” phase.
With Kali’s built-in programs, you can easily collect data about your targets (e.g.
hardware, software, database, plugins, etc.).
Assessment of Weaknesses – Analyze the information you collected and identify
the potential weaknesses of the target. Your knowledge and experience will help
you in this task. Obviously, you need to work on the obvious weaknesses first.
That’s because these weaknesses attract black hat hackers.
Exploitation – Now that you know the specific weaknesses of your target, you must
perform an attack. You will “exploit” a weakness by attacking it with a hacking
tool.
Preparation and Submission of Output – Record all the information you gathered
during the test. Arrange the data so that your clients can easily determine the next
steps. Make sure that your report is clearly explained. Don’t use jargon.
Penetration testers divide tests into two categories: manual and automated. Manual tests
rely on the skills of a white hat hacker. The tester has complete control over the process. If
he makes a mistake, the entire penetration test can prove to be useless. Automated tests,
on the other hand, don’t need human intervention. Once the test runs, the computer will
take care of everything: from selecting targets to recording the results.
In this part of the book, you’ll learn important information regarding these types of tests.
You need to master this concept if you’re serious about hacking. With this knowledge, you
can easily determine the type of test that must be used in any situation.
Manual Penetration Tests
You will run manual tests most of the time. Here, you will use your tools, skills, and
knowledge to find the weaknesses of a network.
Manual tests involve the following steps:
Research – This step has a huge influence over the entire process. If you have a lot
of information about your target, attacking it will be easy. You can conduct research
using the internet. For example, you may look for specific information manually or
run your hacking tools.
Kali Linux has a wide of range of tools that you can use in this “reconnaissance” phase.
With Kali’s built-in programs, you can easily collect data about your targets (e.g.
hardware, software, database, plugins, etc.).
Assessment of Weaknesses – Analyze the information you collected and identify
the potential weaknesses of the target. Your knowledge and experience will help
you in this task. Obviously, you need to work on the obvious weaknesses first.
That’s because these weaknesses attract black hat hackers.
Exploitation – Now that you know the specific weaknesses of your target, you must
perform an attack. You will “exploit” a weakness by attacking it with a hacking
tool.
Preparation and Submission of Output – Record all the information you gathered
during the test. Arrange the data so that your clients can easily determine the next
steps. Make sure that your report is clearly explained. Don’t use jargon.
