0:00 Music 0:06 What is penetration testing? 0:09 So basically, penetration testing is also called pen test. 0:15 And it is legitimate and controlled attack on company based on your agreement with that specific company. 0:24 So company is basically paying you money for you doing the... 0:30 Hacking activities. 0:32 Why hacking activities? 0:34 Because you are using all the tools which are used by hackers and hackers are using the tools for penetration testing and penetration testers are using the tools for hacking. 0:46 So this is almost the same and they share that specific stuff. 0:53 So, based on the... 0:59 Based on the contract, you are getting the scope. 1:04 And that scope can be website, that scope can be internal network, it can be cloud, it can be a mobile application. 1:11 You sign that contract and you start assessment. 1:14 So this is legitimate ethical hacking. 1:18 So which steps of penetration testing are now on the market and they are not changing for many years? 1:30 There are like eight main steps. 1:32 Some people say like 10 or 7, but usually there are 8. 1:37 And I will walk you through each of those steps. 1:42 Step number one is planning and preparation. 1:44 So you define the scope. 1:47 What means defining the scope? 1:48 You speak with client. 1:51 And he said, I'm paying you this amount of money for this amount of time. 1:56 You're doing this engagement. 1:58 Or he's asking, how much time and money will it take to finish this task? 2:04 Usually, the second scenario works. 2:07 So you provide the evaluation. 2:10 Of their specific scope. 2:12 After, client is saying, look, please do not work during the working hours. 2:19 Do not work at weekends because our SOC team will not see what you're doing. 2:24 And do not overload the server with more than 50... 2:30 Megabytes per second and please use VPN. 2:34 So this is rules of engagement. 2:35 First of all, you signed the agreement to start something. 2:39 After you put that rules of engagement into that additional paper. 2:47 Obviously, you sign NDA because without signing NDA, it is very hard to start work because it should be guaranteed that if you are finding... 3:00 materials, if you are finding some sensitive data, you will not expose it. 3:04 So usually it is very important to have a trust to the guy who is going to do pen test because he is literally can exfiltrate all your company data and this is what he's doing, like legitimately. 3:19 So NDA is also 3:22 science. 3:22 So legal permissions. 3:26 So which system can we test? 3:28 What are the limits? 3:29 And who basically will get the report and which report do you want to get? 3:33 After you finish that paperwork, which is usually done by management, who is controlling that 3:41 account and specialists is starting on step two, three and further. 3:47 So reconnaissance is starting and on the reconnaissance stage, you are basically collecting the data about the target. 3:57 You analyze emails, finding domains, credentials and more stuff. 4:03 On the next slides, I will go deeper on each stage. 4:06 After, there is scanning and enumeration. 4:09 So you need to scan system to find vulnerabilities. 4:13 So on step two, again, you just collect passively information. 4:17 How? 4:17 I will show you in details. 4:19 In step three, you start to do scanning and enumeration. 4:22 So you start to do like more active phase. 4:26 You start to port scan. 4:28 You start to find... 4:30 find open directories, you start to find backups, you start to find potential leaks, a lot of information. 4:38 Step four is one of the most important. 4:41 You start to run automatic web vulnerability scanners. 4:45 You start to run tools which can detect known vulnerabilities. 4:49 And on step five, you have basically information from step two, three, and four, and you can start to exploit the found vulnerability. 4:58 So what is vulnerability? 5:00 Vulnerability is something that can allow you to... 5:06 Exfiltrate information, which can allow you to basically hack the specific server and exfiltrate information. 5:16 It can allow you to exfiltrate some part of information. 5:20 It can allow you to put down the server. 5:22 So vulnerability, there are different types of vulnerabilities, and I will tell you about most of the types of vulnerabilities, so you will understand which types of vulnerabilities are known. 5:35 So on step five, you exploit found vulnerabilities. 5:40 So there is usually a big gap between finding vulnerabilities and explaining vulnerabilities. 5:49 Because when you find vulnerability, 5:52 you can stop and you can report to the client and you can say, look, I found very critical vulnerability. 5:57 Do you want me to continue exploiting? 6:00 Some clients are saying, okay, you can continue doing this. 6:05 Some will say, stop. 6:06 No, this is like too much. 6:08 We didn't expect you that you will get that much far. 6:11 So it's also very important to understand that there is penetration testing and there is vulnerability assessment and rate teaming. 6:19 During rate teaming, you potentially, based on the contract, you don't even need to ask sometimes. 6:26 So if you see the system which is hackable, you basically hack it and you try to expand on that system to further systems. 6:36 If this is vulnerability assessment, 6:38 Obviously, what you are doing is you are not going to the step five. 6:43 So you don't exploit. 6:45 Obviously, you don't go to post-exploitation. 6:48 So what is post-exploitation? 6:49 It's when you hack something, right? 6:52 You start to elevate privileges. 6:54 You hack the user. 6:55 And you want to become admin. 6:57 You hack the user. 6:58 You want to hack all the users. 7:00 You're having the same vulnerability. 7:03 After step seven, it is reporting. 7:05 And step eight is remediation. 7:07 So here is the better breakdown. 7:11 On step one, again, we just define the scope and we finish all the legal stuff. 7:18 Just some example of tools which is used in penetration testing for finding vulnerabilities. 7:26 So the most common one, maybe you heard about it. 7:30 It is Nmap. 7:31 So that tool, if you will download the tool, it is a free tool. 7:35 It's called Nmap. 7:37 You can just download it and run it against any host. 7:41 So it will find ports. 7:44 So a host, ports, tools, it can be a little bit complex for people who don't know that stuff. 7:50 So let me break it down. 7:52 Each website usually, by default, is running on port 80. 7:58 So developers know that port 22 is usually used for SSH. 8:05 Also, there are like RDP, MySQL, FTP, and a lot of different protocols. 8:13 And all those protocols, they could be vulnerable the same way as web. 8:19 So based on this information, we need to collect all those ports and be sure that we know exactly which protocols are running. 8:32 Because if we are hacking the website and the database is open, do we need to hack the website? 8:37 I think no. 8:38 Why do we need to have the website if the database is open? 8:41 You can just connect and download the database. 8:43 So first stage is obviously collection of information, running the tools which can allow you to find the ports. 8:52 And after, you just need to work with each port. 8:56 HTTP is usually hosting the website. 9:00 are the most advanced technology which we are having among the different ports. 9:10 For example, if we compare HTTP protocol with FTP, in FTP you just store the 9:19 folders, right, and files. 9:21 In SSH, you can run some commands, right, but that protocol is very limited. 9:25 On the website, big amount of technologies is used on the website. 9:31 So web sites are the most critical stuff, and mostly the websites are having most of the vulnerabilities. 9:40 There are some commercial tools which you can also check. 9:43 It's a Kinetics, Nessus, and a Sparker Burp Suite. 9:45 And I will show you the examples of reports from all those tools. 9:51 You will see the reports. 9:52 So guys, who purchases those tools, they have ability to open the tool. 10:00 Input their website or input their subnet, and I will show you the report and how to do it. 10:06 So it's like pretty easy. 10:08 In Nmap or in similar software, there are like 15 similar software, and they all scan TCP ports and UDP ports. 10:19 So there are two types of... 10:22 Two types of protocols which you can scan, TCP and UDP. 10:27 So you can start the service. 10:30 on the UDP port. 10:32 And if you scan only TCP ports, you will not see the specific port open on the server. 10:39 So there are 65,535 ports on each. 10:45 So you need to scan two times by 65. 10:50 Thousand to find all. 10:53 But hackers are not doing that stuff because it's not like really smart, it's taking time. 10:59 So they just use top 100 ports. 11:02 Top 100 ports are usually known ports to be deployed by common services. 11:09 So hackers are usually skipping the full scan 11:14 to save time. 11:16 But if they are not getting what they need, they can rescan using the full amount of ports. 11:23 So on port 80, you can deploy RDP, potentially. 11:28 You can do it. 11:29 On port 80, you can deploy SSH. 11:32 You can do whatever you want. 11:33 On any port, you can deploy whatever you want. 11:36 It doesn't matter. 11:38 So how the system works? 11:40 It will connect to that specific protocol. 11:45 It will grab the banner. 11:46 And based on the banner, it will detect the protocol. 11:51 So what is banner? 11:52 Banner is when you are creating the socket, 11:57 with the specific port. 12:00 That port should send you banner by default. 12:03 That banner can be like, for example, SMTP will say, hello, I'm SMTP server. 12:09 And based on that banner, even if it will be port 80 or 443, you will be able to understand it.
0:00 Music 0:06 What is penetration testing? 0:09 So basically, penetration testing is also called pen test. 0:15 And it is legitimate and controlled attack on company based on your agreement with that specific company. 0:24 So company is basically paying you money for you doing the... 0:30 Hacking activities. 0:32 Why hacking activities? 0:34 Because you are using all the tools which are used by hackers and hackers are using the tools for penetration testing and penetration testers are using the tools for hacking. 0:46 So this is almost the same and they share that specific stuff. 0:53 So, based on the... 0:59 Based on the contract, you are getting the scope. 1:04 And that scope can be website, that scope can be internal network, it can be cloud, it can be a mobile application. 1:11 You sign that contract and you start assessment. 1:14 So this is legitimate ethical hacking. 1:18 So which steps of penetration testing are now on the market and they are not changing for many years? 1:30 There are like eight main steps. 1:32 Some people say like 10 or 7, but usually there are 8. 1:37 And I will walk you through each of those steps. 1:42 Step number one is planning and preparation. 1:44 So you define the scope. 1:47 What means defining the scope? 1:48 You speak with client. 1:51 And he said, I'm paying you this amount of money for this amount of time. 1:56 You're doing this engagement. 1:58 Or he's asking, how much time and money will it take to finish this task? 2:04 Usually, the second scenario works. 2:07 So you provide the evaluation. 2:10 Of their specific scope. 2:12 After, client is saying, look, please do not work during the working hours. 2:19 Do not work at weekends because our SOC team will not see what you're doing. 2:24 And do not overload the server with more than 50... 2:30 Megabytes per second and please use VPN. 2:34 So this is rules of engagement. 2:35 First of all, you signed the agreement to start something. 2:39 After you put that rules of engagement into that additional paper. 2:47 Obviously, you sign NDA because without signing NDA, it is very hard to start work because it should be guaranteed that if you are finding... 3:00 materials, if you are finding some sensitive data, you will not expose it. 3:04 So usually it is very important to have a trust to the guy who is going to do pen test because he is literally can exfiltrate all your company data and this is what he's doing, like legitimately. 3:19 So NDA is also 3:22 science. 3:22 So legal permissions. 3:26 So which system can we test? 3:28 What are the limits? 3:29 And who basically will get the report and which report do you want to get? 3:33 After you finish that paperwork, which is usually done by management, who is controlling that 3:41 account and specialists is starting on step two, three and further. 3:47 So reconnaissance is starting and on the reconnaissance stage, you are basically collecting the data about the target. 3:57 You analyze emails, finding domains, credentials and more stuff. 4:03 On the next slides, I will go deeper on each stage. 4:06 After, there is scanning and enumeration. 4:09 So you need to scan system to find vulnerabilities. 4:13 So on step two, again, you just collect passively information. 4:17 How? 4:17 I will show you in details. 4:19 In step three, you start to do scanning and enumeration. 4:22 So you start to do like more active phase. 4:26 You start to port scan. 4:28 You start to find... 4:30 find open directories, you start to find backups, you start to find potential leaks, a lot of information. 4:38 Step four is one of the most important. 4:41 You start to run automatic web vulnerability scanners. 4:45 You start to run tools which can detect known vulnerabilities. 4:49 And on step five, you have basically information from step two, three, and four, and you can start to exploit the found vulnerability. 4:58 So what is vulnerability? 5:00 Vulnerability is something that can allow you to... 5:06 Exfiltrate information, which can allow you to basically hack the specific server and exfiltrate information. 5:16 It can allow you to exfiltrate some part of information. 5:20 It can allow you to put down the server. 5:22 So vulnerability, there are different types of vulnerabilities, and I will tell you about most of the types of vulnerabilities, so you will understand which types of vulnerabilities are known. 5:35 So on step five, you exploit found vulnerabilities. 5:40 So there is usually a big gap between finding vulnerabilities and explaining vulnerabilities. 5:49 Because when you find vulnerability, 5:52 you can stop and you can report to the client and you can say, look, I found very critical vulnerability. 5:57 Do you want me to continue exploiting? 6:00 Some clients are saying, okay, you can continue doing this. 6:05 Some will say, stop. 6:06 No, this is like too much. 6:08 We didn't expect you that you will get that much far. 6:11 So it's also very important to understand that there is penetration testing and there is vulnerability assessment and rate teaming. 6:19 During rate teaming, you potentially, based on the contract, you don't even need to ask sometimes. 6:26 So if you see the system which is hackable, you basically hack it and you try to expand on that system to further systems. 6:36 If this is vulnerability assessment, 6:38 Obviously, what you are doing is you are not going to the step five. 6:43 So you don't exploit. 6:45 Obviously, you don't go to post-exploitation. 6:48 So what is post-exploitation? 6:49 It's when you hack something, right? 6:52 You start to elevate privileges. 6:54 You hack the user. 6:55 And you want to become admin. 6:57 You hack the user. 6:58 You want to hack all the users. 7:00 You're having the same vulnerability. 7:03 After step seven, it is reporting. 7:05 And step eight is remediation. 7:07 So here is the better breakdown. 7:11 On step one, again, we just define the scope and we finish all the legal stuff. 7:18 Just some example of tools which is used in penetration testing for finding vulnerabilities. 7:26 So the most common one, maybe you heard about it. 7:30 It is Nmap. 7:31 So that tool, if you will download the tool, it is a free tool. 7:35 It's called Nmap. 7:37 You can just download it and run it against any host. 7:41 So it will find ports. 7:44 So a host, ports, tools, it can be a little bit complex for people who don't know that stuff. 7:50 So let me break it down. 7:52 Each website usually, by default, is running on port 80. 7:58 So developers know that port 22 is usually used for SSH. 8:05 Also, there are like RDP, MySQL, FTP, and a lot of different protocols. 8:13 And all those protocols, they could be vulnerable the same way as web. 8:19 So based on this information, we need to collect all those ports and be sure that we know exactly which protocols are running. 8:32 Because if we are hacking the website and the database is open, do we need to hack the website? 8:37 I think no. 8:38 Why do we need to have the website if the database is open? 8:41 You can just connect and download the database. 8:43 So first stage is obviously collection of information, running the tools which can allow you to find the ports. 8:52 And after, you just need to work with each port. 8:56 HTTP is usually hosting the website. 9:00 are the most advanced technology which we are having among the different ports. 9:10 For example, if we compare HTTP protocol with FTP, in FTP you just store the 9:19 folders, right, and files. 9:21 In SSH, you can run some commands, right, but that protocol is very limited. 9:25 On the website, big amount of technologies is used on the website. 9:31 So web sites are the most critical stuff, and mostly the websites are having most of the vulnerabilities. 9:40 There are some commercial tools which you can also check. 9:43 It's a Kinetics, Nessus, and a Sparker Burp Suite. 9:45 And I will show you the examples of reports from all those tools. 9:51 You will see the reports. 9:52 So guys, who purchases those tools, they have ability to open the tool. 10:00 Input their website or input their subnet, and I will show you the report and how to do it. 10:06 So it's like pretty easy. 10:08 In Nmap or in similar software, there are like 15 similar software, and they all scan TCP ports and UDP ports. 10:19 So there are two types of... 10:22 Two types of protocols which you can scan, TCP and UDP. 10:27 So you can start the service. 10:30 on the UDP port. 10:32 And if you scan only TCP ports, you will not see the specific port open on the server. 10:39 So there are 65,535 ports on each. 10:45 So you need to scan two times by 65. 10:50 Thousand to find all. 10:53 But hackers are not doing that stuff because it's not like really smart, it's taking time. 10:59 So they just use top 100 ports. 11:02 Top 100 ports are usually known ports to be deployed by common services. 11:09 So hackers are usually skipping the full scan 11:14 to save time. 11:16 But if they are not getting what they need, they can rescan using the full amount of ports. 11:23 So on port 80, you can deploy RDP, potentially. 11:28 You can do it. 11:29 On port 80, you can deploy SSH. 11:32 You can do whatever you want. 11:33 On any port, you can deploy whatever you want. 11:36 It doesn't matter. 11:38 So how the system works? 11:40 It will connect to that specific protocol. 11:45 It will grab the banner. 11:46 And based on the banner, it will detect the protocol. 11:51 So what is banner? 11:52 Banner is when you are creating the socket, 11:57 with the specific port. 12:00 That port should send you banner by default. 12:03 That banner can be like, for example, SMTP will say, hello, I'm SMTP server. 12:09 And based on that banner, even if it will be port 80 or 443, you will be able to understand it.