Chuyển đến nội dung chính

Lesson 11: Pentest Fundamentals — Process and Legal Framework

Scope definition, Rules of Engagement, authorization, Black/White/Gray box, ethical hacking code of conduct.

🔒 DevSecOps — Lesson 11 Lesson 11: Pentest Fundamentals — Process__HTMLTAG_53___ and Legal Framework

Performance Testing & Pentest: Enterprise Standard Process 2026

Part 3: Pentest Foundations — Process and Methodology

xdev.asia

1. What is Penetration Testing?

Penetration Testing (Pentest) is the process of simulating a controlled attack on an IT system, to detect security vulnerabilities before attackers actually exploit them.

Vulnerability Assessment vs Penetration Testing:

Vulnerability Assessment:
  ├── Automated scanning (Nessus, Qualys)
  ├── Tìm danh sách vulnerabilities
  ├── Không exploit
  └── Breadth-first approach

Penetration Testing:
  ├── Manual + Automated
  ├── Exploit vulnerabilities (có PoC)
  ├── Chain vulnerabilities → impact
  └── Depth-first approach

Kết hợp cả hai → Comprehensive security assessment

2. Types of Pentest

TypeKnowledge pentester hasSimulation
Black BoxDon't know anything about the systemExternal attacker_
Gray BoxHas credentials, partial docsInsider / compromised account
White BoxFull source code, architectureComprehensive audit
Phân loại theo scope:

Network Pentest:
  ├── External: Test từ Internet vào
  └── Internal: Test từ bên trong mạng

Web Application Pentest:
  ├── DAST (Dynamic Application Security Testing)
  └── IAST (Interactive — runtime instrumentation)

Mobile Application Pentest:
  ├── Android (APK decompilation, runtime analysis)
  └── iOS (IPA analysis, jailbreak testing)

Cloud Pentest:
  ├── AWS / Azure / GCP misconfigurations
  └── IAM, storage, compute, networking

Social Engineering:
  ├── Phishing campaigns
  └── Physical security testing

Wireless Pentest:
  └── WiFi, Bluetooth, RFID

3. Rules of Engagement (ROE)

ROE Document Template:

1. SCOPE
   ✅ In-scope:
   - 10.0.0.0/24 (production network)
   - api.example.com, app.example.com
   - AWS account 123456789012
   
   ❌ Out-of-scope:
   - Third-party services (Stripe, Twilio)
   - Physical premises
   - Social engineering attacks
   - DDoS / Denial of Service

2. TIMELINE
   - Start: 2026-04-01T08:00Z
   - End: 2026-04-14T18:00Z
   - Testing hours: 08:00 - 22:00 ICT (UTC+7)

3. AUTHORIZATION
   - Signed by: CTO Nguyễn Văn A
   - Emergency contact: +84-xxx-xxx-xxxx
   - Escalation: [email protected]

4. CONSTRAINTS
   - No data destruction or modification
   - No production database changes
   - Stop immediately if PII exposed
   - Report critical findings immediately

5. COMMUNICATION
   - Daily status updates via secure channel
   - Critical findings: Immediate phone call
   - Report deadline: 7 days after testing ends
Vietnam:
  ├── Luật An ninh mạng 2018 (Luật số 24/2018/QH14)
  ├── Nghị định 13/2023/NĐ-CP (Bảo vệ dữ liệu cá nhân)
  ├── Thông tư 12/2022/TT-BTTTT (Đánh giá an toàn thông tin)
  └── Cần authorization bằng văn bản trước khi test

International:
  ├── CFAA (US - Computer Fraud and Abuse Act)
  ├── CMA (UK - Computer Misuse Act)
  ├── GDPR (EU - data protection implications)
  └── Authorized testing ≠ Hacking

Key principles:
  ✅ ALWAYS have written authorization
  ✅ NEVER test without explicit permission
  ✅ NEVER exceed agreed scope
  ✅ Handle discovered data responsibly
  ✅ Report all findings, even accidental discoveries

5. Ethical Hacking Code of Conduct

Professional Ethics:
  1. Integrity: Báo cáo trung thực, không giấu findings
  2. Confidentiality: Bảo mật thông tin khách hàng
  3. Authorization: Chỉ test trong phạm vi được phép
  4. Non-destructive: Không gây hại cho hệ thống
  5. Responsible Disclosure: Báo cáo trước khi public
  6. Documentation: Ghi chép đầy đủ mọi hành động
  7. Professionalism: Maintain trust và reputation

Anti-patterns:
  ❌ Giữ lại backdoors sau khi test
  ❌ Exfiltrate data không cần thiết
  ❌ Test ngoài giờ/scope được phép
  ❌ Share findings với bên thứ ba
  ❌ Dùng findings cho mục đích cá nhân

6. Summary

  • Pentest: Simulate controlled attacks, find vulnerabilities + exploits + reports
  • Types: Black/Gray/White box, Network/Web/Cloud/Mobile
  • ROE: Document scope, timeline, authorization, constraints
  • Legal: ALWAYS have written authorization, comply with the law
  • Ethics: Integrity, confidentiality, responsible disclosure

The next article will learn PTES — Penetration Testing Execution Standard.