Uncover Security Weakness Before the Attacker Through Penetration Testing
Christian D. Hines, Md Minhaz Chowdhury · 2022
Penetration testing is the practice of ethical hacking of a company’s resources by a professional to find vulnerabilities to the network, systems, software, and web applications. This paper explains the concepts of penetration testing. The purpose of the test is twofold: first, to uncover vulnerabilities before an attacker can exploit them; and second, to exploit the vulnerabilities in a safe environment to learn the true gravity of each vulnerability. There are a series of steps followed during this process. First is the information gathering stage. This is the process of collecting information about the company and its employees from public sources or by interacting with the company directly. Next is vulnerability scanning, this includes vigorous scanning of machines to determine the software and operating system versions running on them to better understand how to exploit them. Then the actual exploitation happens; the vulnerabilities are taken advantage of to gain privileged access to the machine and the information on it. Finally, a report is written up detailing each vulnerability, and what was gained by exploiting them. This is an invaluable resource for companies because they experience a realistic attack with minimal risk to their assets and can use that information to shore up their defenses. This paper aims to detail the processes of penetration testing and some of the tools used therein.