Penetration Testing
In short: In a penetration test (pentest) authorised specialists attack a system to find weaknesses before criminals do.
In more detail: The written permission is important. Without it even scans are legally delicate (§ 202c StGB, the “hacker paragraph”).
In Depth
Process
- Agreement and scope.
- Information gathering.
- Vulnerability analysis.
- Exploitation (controlled).
- Report with recommendations.
Types
Black box, grey box and white box depending on the testers’ prior knowledge.
Tools
nmap, Metasploit, Burp Suite, Hydra. See exploit.
See also: Black-box Testing, White-box Testing, Nmap, Exploit