Chuyển đến nội dung chính

Bài 11: Pentest Fundamentals — Quy trình và Khung pháp lý

Scope definition, Rules of Engagement, authorization, Black/White/Gray box, ethical hacking code of conduct.

🔒 DevSecOps — Bài 11 Bài 11: Pentest Fundamentals — Quy trình và Khung pháp lý

Performance Testing & Pentest: Quy trình Chuẩn Doanh nghiệp 2026

Phần 3: Pentest Foundations — Quy trình và Phương pháp luận

xdev.asia

1. Penetration Testing là gì?

Penetration Testing (Pentest) là quá trình mô phỏng cuộc tấn công có kiểm soát vào hệ thống IT, nhằm phát hiện lỗ hổng bảo mật trước khi kẻ tấn công thực sự khai thác chúng.

Vulnerability Assessment vs Penetration Testing:

Vulnerability Assessment:
  ├── Automated scanning (Nessus, Qualys)
  ├── Tìm danh sách vulnerabilities
  ├── Không exploit
  └── Breadth-first approach

Penetration Testing:
  ├── Manual + Automated
  ├── Exploit vulnerabilities (có PoC)
  ├── Chain vulnerabilities → impact
  └── Depth-first approach

Kết hợp cả hai → Comprehensive security assessment

2. Các loại Pentest

LoạiKiến thức pentester cóMô phỏng
Black BoxKhông biết gì về hệ thốngExternal attacker
Gray BoxCó credentials, partial docsInsider / compromised account
White BoxFull source code, architectureComprehensive audit
Phân loại theo scope:

Network Pentest:
  ├── External: Test từ Internet vào
  └── Internal: Test từ bên trong mạng

Web Application Pentest:
  ├── DAST (Dynamic Application Security Testing)
  └── IAST (Interactive — runtime instrumentation)

Mobile Application Pentest:
  ├── Android (APK decompilation, runtime analysis)
  └── iOS (IPA analysis, jailbreak testing)

Cloud Pentest:
  ├── AWS / Azure / GCP misconfigurations
  └── IAM, storage, compute, networking

Social Engineering:
  ├── Phishing campaigns
  └── Physical security testing

Wireless Pentest:
  └── WiFi, Bluetooth, RFID

3. Rules of Engagement (ROE)

ROE Document Template:

1. SCOPE
   ✅ In-scope:
   - 10.0.0.0/24 (production network)
   - api.example.com, app.example.com
   - AWS account 123456789012
   
   ❌ Out-of-scope:
   - Third-party services (Stripe, Twilio)
   - Physical premises
   - Social engineering attacks
   - DDoS / Denial of Service

2. TIMELINE
   - Start: 2026-04-01T08:00Z
   - End: 2026-04-14T18:00Z
   - Testing hours: 08:00 - 22:00 ICT (UTC+7)

3. AUTHORIZATION
   - Signed by: CTO Nguyễn Văn A
   - Emergency contact: +84-xxx-xxx-xxxx
   - Escalation: [email protected]

4. CONSTRAINTS
   - No data destruction or modification
   - No production database changes
   - Stop immediately if PII exposed
   - Report critical findings immediately

5. COMMUNICATION
   - Daily status updates via secure channel
   - Critical findings: Immediate phone call
   - Report deadline: 7 days after testing ends
Vietnam:
  ├── Luật An ninh mạng 2018 (Luật số 24/2018/QH14)
  ├── Nghị định 13/2023/NĐ-CP (Bảo vệ dữ liệu cá nhân)
  ├── Thông tư 12/2022/TT-BTTTT (Đánh giá an toàn thông tin)
  └── Cần authorization bằng văn bản trước khi test

International:
  ├── CFAA (US - Computer Fraud and Abuse Act)
  ├── CMA (UK - Computer Misuse Act)
  ├── GDPR (EU - data protection implications)
  └── Authorized testing ≠ Hacking

Key principles:
  ✅ ALWAYS have written authorization
  ✅ NEVER test without explicit permission
  ✅ NEVER exceed agreed scope
  ✅ Handle discovered data responsibly
  ✅ Report all findings, even accidental discoveries

5. Ethical Hacking Code of Conduct

Professional Ethics:
  1. Integrity: Báo cáo trung thực, không giấu findings
  2. Confidentiality: Bảo mật thông tin khách hàng
  3. Authorization: Chỉ test trong phạm vi được phép
  4. Non-destructive: Không gây hại cho hệ thống
  5. Responsible Disclosure: Báo cáo trước khi public
  6. Documentation: Ghi chép đầy đủ mọi hành động
  7. Professionalism: Maintain trust và reputation

Anti-patterns:
  ❌ Giữ lại backdoors sau khi test
  ❌ Exfiltrate data không cần thiết
  ❌ Test ngoài giờ/scope được phép
  ❌ Share findings với bên thứ ba
  ❌ Dùng findings cho mục đích cá nhân

6. Tổng kết

  • Pentest: Mô phỏng tấn công có kiểm soát, tìm lỗ hổng + exploit + báo cáo
  • Types: Black/Gray/White box, Network/Web/Cloud/Mobile
  • ROE: Document scope, timeline, authorization, constraints
  • Legal: ALWAYS có written authorization, tuân thủ pháp luật
  • Ethics: Integrity, confidentiality, responsible disclosure

Bài tiếp theo sẽ tìm hiểu PTES — Penetration Testing Execution Standard.