1. What is Penetration Testing?
Penetration Testing (Pentest) is the process of simulating a controlled attack on an IT system, to detect security vulnerabilities before attackers actually exploit them.
Vulnerability Assessment vs Penetration Testing:
Vulnerability Assessment:
├── Automated scanning (Nessus, Qualys)
├── Tìm danh sách vulnerabilities
├── Không exploit
└── Breadth-first approach
Penetration Testing:
├── Manual + Automated
├── Exploit vulnerabilities (có PoC)
├── Chain vulnerabilities → impact
└── Depth-first approach
Kết hợp cả hai → Comprehensive security assessment
2. Types of Pentest
| Type | Knowledge pentester has | Simulation |
|---|---|---|
| Black Box | Don't know anything about the system | External attacker_ |
| Gray Box | Has credentials, partial docs | Insider / compromised account |
| White Box | Full source code, architecture | Comprehensive audit |
Phân loại theo scope:
Network Pentest:
├── External: Test từ Internet vào
└── Internal: Test từ bên trong mạng
Web Application Pentest:
├── DAST (Dynamic Application Security Testing)
└── IAST (Interactive — runtime instrumentation)
Mobile Application Pentest:
├── Android (APK decompilation, runtime analysis)
└── iOS (IPA analysis, jailbreak testing)
Cloud Pentest:
├── AWS / Azure / GCP misconfigurations
└── IAM, storage, compute, networking
Social Engineering:
├── Phishing campaigns
└── Physical security testing
Wireless Pentest:
└── WiFi, Bluetooth, RFID
3. Rules of Engagement (ROE)
ROE Document Template:
1. SCOPE
✅ In-scope:
- 10.0.0.0/24 (production network)
- api.example.com, app.example.com
- AWS account 123456789012
❌ Out-of-scope:
- Third-party services (Stripe, Twilio)
- Physical premises
- Social engineering attacks
- DDoS / Denial of Service
2. TIMELINE
- Start: 2026-04-01T08:00Z
- End: 2026-04-14T18:00Z
- Testing hours: 08:00 - 22:00 ICT (UTC+7)
3. AUTHORIZATION
- Signed by: CTO Nguyễn Văn A
- Emergency contact: +84-xxx-xxx-xxxx
- Escalation: [email protected]
4. CONSTRAINTS
- No data destruction or modification
- No production database changes
- Stop immediately if PII exposed
- Report critical findings immediately
5. COMMUNICATION
- Daily status updates via secure channel
- Critical findings: Immediate phone call
- Report deadline: 7 days after testing ends
4. Legal framework
Vietnam:
├── Luật An ninh mạng 2018 (Luật số 24/2018/QH14)
├── Nghị định 13/2023/NĐ-CP (Bảo vệ dữ liệu cá nhân)
├── Thông tư 12/2022/TT-BTTTT (Đánh giá an toàn thông tin)
└── Cần authorization bằng văn bản trước khi test
International:
├── CFAA (US - Computer Fraud and Abuse Act)
├── CMA (UK - Computer Misuse Act)
├── GDPR (EU - data protection implications)
└── Authorized testing ≠ Hacking
Key principles:
✅ ALWAYS have written authorization
✅ NEVER test without explicit permission
✅ NEVER exceed agreed scope
✅ Handle discovered data responsibly
✅ Report all findings, even accidental discoveries
5. Ethical Hacking Code of Conduct
Professional Ethics:
1. Integrity: Báo cáo trung thực, không giấu findings
2. Confidentiality: Bảo mật thông tin khách hàng
3. Authorization: Chỉ test trong phạm vi được phép
4. Non-destructive: Không gây hại cho hệ thống
5. Responsible Disclosure: Báo cáo trước khi public
6. Documentation: Ghi chép đầy đủ mọi hành động
7. Professionalism: Maintain trust và reputation
Anti-patterns:
❌ Giữ lại backdoors sau khi test
❌ Exfiltrate data không cần thiết
❌ Test ngoài giờ/scope được phép
❌ Share findings với bên thứ ba
❌ Dùng findings cho mục đích cá nhân
6. Summary
- Pentest: Simulate controlled attacks, find vulnerabilities + exploits + reports
- Types: Black/Gray/White box, Network/Web/Cloud/Mobile
- ROE: Document scope, timeline, authorization, constraints
- Legal: ALWAYS have written authorization, comply with the law
- Ethics: Integrity, confidentiality, responsible disclosure
The next article will learn PTES — Penetration Testing Execution Standard.