Penetration Test: attack simulation through Ethical Hacking techniques

The expression “Penetration Test” refers to a set of methodologies and techniques adopted in the field of Cybersecurity offensive, aiming at identifying and exploiting the highest number of vulnerabilities to determine the level of risk of each one of them. Among the advantages of a Penetration Test, compared to an usual Vulnerability Assessment, is indeed its capacity to detect the presence of vulnerabilities during its execution, without the need of any assessment action afterwards.

Depending on the level of depth being sought with the test, it is possible for the technical staff to try to discover even new vulnerabilities (0-day exploits), however, an approach more oriented to identify vulnerabilities already known, but not less dangerous, is commonly adopted. After all, the exploits-related techniques and execution are accessible to anyone nowadays, and their ease of use, together with the large amount of teaching material on the web, has made available to anyone the most common techniques. Unfortunately, these techniques, despite requiring not too deep technical skills to be used, are more than sufficient to compromise a system or even a whole infrastructure, if is left inadequately protected and monitored.

Once it has reached its target, a Penetration Tester worthy of its name will not stop, but will go on trying to find other entry points, and, if necessary, will try new ways combining different techniques and attacks, until the target will eventually be reached.

Penetration test types

There are different types of Penetration Tests, depending on the aspect that needs to be tested:

  • External Penetration Test: this process aims at identifying and then exploiting vulnerabilities existing on the external perimeter of the network, with the ultimate goal of gaining internal access to the Infrastructure.
  • Internal Penetration Test: it is the simulation of the intrusion into a company’s network by a malevolent user within the same organization, such as a malicious employee. It is also the simulation of the compromission of a computer or a company’s account by an external actor.
  • Web Application Penetration Test (WAPT): it is an assessment performed on a Web application, with the aim of assessing vulnerabilities, unauthorized access or exposure of sensitive data.
  • Mobile Assessment: it is an assessment performed on applications for mobile devices. It consists of a statistical analysis of the application package as well of a dynamic analysis, with the aim of identifying vulnerabilities on the data flow sent and/or received by the application.
  • IOT Assessment: it is a type of assessment which tries to identify vulnerabilities in the IOT devices, including attempts of exploiting the firmware or altering the data sent and/or received by the device.
  • Wireless Assessment: it is a type of Assessment which covers the field of Wireless solutions, among which 802.x, Bluetooth and so forth.

Phases of a Penetration Test

A Penetration Test on an infrastructure, in its most complete form which includes both External and Internal type, consists of the following phases:

  1. Reconnaissance and Information Gathering

The first step of an attack consists in researching on the net as much information as possible on the target. This information may relate to architecture and types of platforms employed, active services or work e-mail addresses. All information build up the so called “Attack Surface”.

  1. Vulnerability Identification and Attack Modeling

Relying on the information gathered in the previous step it is possible to proceed to the modeling of an attack plan, which may exploits both weak spots in the external network perimeter and Social Engineering. The goal of the latter is to exploits the “Human Factor” to gain the first access to the network.

  1. Exploitation / Access gain

This is the real compromission phase, in which the attack planned in the previous step is executed. The aim is to gain the first access to the target network and therefore it is also the most delicate phase of the entire process. Thus, the effectiveness of all countermeasures active in the client’s network will be assessed: Intrusion Detection & Prevention System, Firewall, Antivirus, EDR/XDR, Antispam, SSL Inspection, Proxy and so forth.

  1. Post-Exploitation

The Post-Exploitation phase consists itself of few steps. Each one of them allows the attacker to gain more privileges and to move within the network, remaining invisible to protection and monitoring systems. Some of these steps are the following:

  • Maintaining Access: after a Host has been compromised, it is a good idea to ensure persistent access to the target network.
  • Privilege Escalation: a series of techniques which allow the attacker to elevate its privileges within the network or each Host.
  • Lateral Movement: a series of techniques which allow the attacker to move from Host to Host, or from Subnet to Subnet, exploiting misconfiguration and/or privileges gained during the Escalation phase.
  1. Covering Tracks

Simulating a real scenario, the last operational phase proves how an attacker could erase any trace of its action within the network, thus making it extremely difficult, if not impossible, to analyze the computer incident afterwards. Furthermore, this step is useful to test the real effectiveness of the Log and Incident Response analysis systems.

  1. Reporting

At the end of the External Penetration Test, the Penetration Tester will be in charge of drawing up a report as detailed as possible on the entire attack process. This report will be firstly handed over and illustrated to the client, so that it can be later shown to the IT network administrators, in order to fix potential vulnerabilities that have resulted from the Penetration Test.

The three pentesting methodologies: BLACK BOX, GREY BOX and WHITE BOX

Finally, a Penetration Test may be performed following different approaches, depending on how much access and knowledge are made accessible to the Penetration Tester before the beginning of the analysis:

  • Black Box: the Penetration Tester operates without any knowledge of internal information and does not possess any access credentials, not even with minimum privileges, to access the client’s infrastructure or application. Such case is also the most common scenario in which a real attacker operates.
  • Grey Box: unlike the Black Box scenario, some access credentials to the system needing to be tested are given to the Penetration Tester. The access level of such credentials has to be agreed with the client during the Engagement phase. Typically, a Grey Box test simulates an attack coming from within the organization’s perimeter and it is usually referred to as Internal Penetration Test, as described above.
  • White Box: In this test type it is assumed that the advisor / Penetration Tester have complete access to the infrastructure or, in the case of an application, to its source code. This particular test provides a complete and comprehensive view, allowing for an assessment of risks from a privileged position, to which a real attacker usually has no access to.

ZAIUX® Evo: the automated Pentest software

Thanks to its software solution, ZAIUX® Evo, Pikered has decided to make a tool guided by Artificial Intelligence available, which is able to perform automated Internal Penetration Tests, allowing for the assessment of vulnerabilities in IT infrastructures through an ongoing approach. ZAIUX® Evo’s execution mode is comparable to that of a manual Penetration Test, making it unnecessary to manually validate the vulnerabilities, which is required after a Vulnerability Assessment. The techniques employed by ZAIUX® Evo tend to emulate as much as possible a real scenario, the whole being guided and planned by an intelligent engine which optimizes timing and resources. ZAIUX® Evo aims at working alongside Penetration Testers and System Administrators in identifying vulnerabilities, which often may pass unnoticed both by a Vulnerability Assessment and a human Penetration Tester. Furthermore, this solution is meant to be a follow up to manual activities, being them Penetration Test or Red-Team related, in order to ongoingly prove the internal resilience of an IT-Infrastructure.