Demonstration of a Penetration Test

binsec academy GmbH Pentest Training

So far, we have looked at the technical processes of an attacker as individual pieces of the puzzle, which still have to be put together in order to create the big picture. Based on our task of carrying out an IT infrastructure penetration test for Dubius Payment Ltd., we will demonstrate a possible procedure for this in a similar scenario. The performance of the penetration test is split into the following four phases:

  1. Identification of the network ranges of a company
  2. Identification of the accessible servers and services
  3. Identification of vulnerabilities
  4. Exploitation of vulnerabilities

To give you a deeper understanding of the procedure of a penetration test, you can download the internal documentation, which was produced during the demo pentest. An internal documentation is the basis for any structured approach, which is why we should record our work steps, particularly since we have to prove to our client the identified vulnerabilities in the final report.

Note: Even though the following procedure with the associated internal documentation is merely an example, every work step and every result should nevertheless be documented immediately. To avoid missing evidence of vulnerabilities after performing a penetration test, so-called proof-of-concepts should be stored in the form of console output or screenshots. For the sake of clarity, tools such as cherrytree, Obsidian or MarkText are excellent documentation tools, since they can be used to arrange hierarchical relationships in a tree structure: Network areas group together IP addresses whose open ports can be used to access services. Each of these resources has its own pentest tasks, the results of which we can store in the associated node:

 - Network N1
    - IP I1
        - Service S1
        - Service S2
    - IP I2
        - Service S3
 - Network N2
    - IP I3
        - Service S4
[...]

Sub Articles

binsec academy GmbH - Online IT Security Training with Practical Focus

binsec academy GmbH is provider of online IT security training, offering practical, lab-based courses for professionals. The academy provides hands-on training in areas such as penetration testing and secure software development. Participants gain practical experience through realistic lab environments, including simulations of company networks and applications. Courses are available in multiple programming languages and align with standards like OWASP Top 10 and PCI DSS. Upon successful completion, participants receive certifications such as the Binsec Academy Certified Pentest Professional (BACPP) and Binsec Academy Certified Secure Coding Professional (BACSCP), demonstrating their ability to identify and remediate security vulnerabilities.

Goto binsec acadmy GmbH

binsec GmbH – Experts in Penetration Testing

binsec GmbH is a German IT security company focused on professional penetration testing. With over 10 years of experience, the team conducts in-depth penetration tests on networks, web applications, APIs, and mobile apps. Certified experts systematically identify and document security vulnerabilities to support organizations in improving their security and meeting compliance requirements.

Goto binsec GmbH

Contact

binsec GmbH
Solmsstraße 41
60486 Frankfurt am Main
Germany

Legal notice

Director: Patrick Sauer
Authorized Officer: Dominik Sauer, Florian Zavatzki
Registration: Frankfurt am Main, HRB97277
Turnover Tax Identification No.: DE290966808