EMZETT.
Login

Penetration Testing

In short: In a penetration test (pentest) authorised specialists attack a system to find weaknesses before criminals do.

In more detail: The written permission is important. Without it even scans are legally delicate (§ 202c StGB, the “hacker paragraph”).

In Depth

Process

  1. Agreement and scope.
  2. Information gathering.
  3. Vulnerability analysis.
  4. Exploitation (controlled).
  5. Report with recommendations.

Types

Black box, grey box and white box depending on the testers’ prior knowledge.

Tools

nmap, Metasploit, Burp Suite, Hydra. See exploit.

See also: Black-box Testing, White-box Testing, Nmap, Exploit