1. Penetration Testing là gì?
Penetration Testing (Pentest) là quá trình mô phỏng cuộc tấn công có kiểm soát vào hệ thống IT, nhằm phát hiện lỗ hổng bảo mật trước khi kẻ tấn công thực sự khai thác chúng.
Vulnerability Assessment vs Penetration Testing:
Vulnerability Assessment:
├── Automated scanning (Nessus, Qualys)
├── Tìm danh sách vulnerabilities
├── Không exploit
└── Breadth-first approach
Penetration Testing:
├── Manual + Automated
├── Exploit vulnerabilities (có PoC)
├── Chain vulnerabilities → impact
└── Depth-first approach
Kết hợp cả hai → Comprehensive security assessment
2. Các loại Pentest
| Loại | Kiến thức pentester có | Mô phỏng |
|---|---|---|
| Black Box | Không biết gì về hệ thống | External attacker |
| Gray Box | Có credentials, partial docs | Insider / compromised account |
| White Box | Full source code, architecture | Comprehensive audit |
Phân loại theo scope:
Network Pentest:
├── External: Test từ Internet vào
└── Internal: Test từ bên trong mạng
Web Application Pentest:
├── DAST (Dynamic Application Security Testing)
└── IAST (Interactive — runtime instrumentation)
Mobile Application Pentest:
├── Android (APK decompilation, runtime analysis)
└── iOS (IPA analysis, jailbreak testing)
Cloud Pentest:
├── AWS / Azure / GCP misconfigurations
└── IAM, storage, compute, networking
Social Engineering:
├── Phishing campaigns
└── Physical security testing
Wireless Pentest:
└── WiFi, Bluetooth, RFID
3. Rules of Engagement (ROE)
ROE Document Template:
1. SCOPE
✅ In-scope:
- 10.0.0.0/24 (production network)
- api.example.com, app.example.com
- AWS account 123456789012
❌ Out-of-scope:
- Third-party services (Stripe, Twilio)
- Physical premises
- Social engineering attacks
- DDoS / Denial of Service
2. TIMELINE
- Start: 2026-04-01T08:00Z
- End: 2026-04-14T18:00Z
- Testing hours: 08:00 - 22:00 ICT (UTC+7)
3. AUTHORIZATION
- Signed by: CTO Nguyễn Văn A
- Emergency contact: +84-xxx-xxx-xxxx
- Escalation: [email protected]
4. CONSTRAINTS
- No data destruction or modification
- No production database changes
- Stop immediately if PII exposed
- Report critical findings immediately
5. COMMUNICATION
- Daily status updates via secure channel
- Critical findings: Immediate phone call
- Report deadline: 7 days after testing ends
4. Khung pháp lý
Vietnam:
├── Luật An ninh mạng 2018 (Luật số 24/2018/QH14)
├── Nghị định 13/2023/NĐ-CP (Bảo vệ dữ liệu cá nhân)
├── Thông tư 12/2022/TT-BTTTT (Đánh giá an toàn thông tin)
└── Cần authorization bằng văn bản trước khi test
International:
├── CFAA (US - Computer Fraud and Abuse Act)
├── CMA (UK - Computer Misuse Act)
├── GDPR (EU - data protection implications)
└── Authorized testing ≠ Hacking
Key principles:
✅ ALWAYS have written authorization
✅ NEVER test without explicit permission
✅ NEVER exceed agreed scope
✅ Handle discovered data responsibly
✅ Report all findings, even accidental discoveries
5. Ethical Hacking Code of Conduct
Professional Ethics:
1. Integrity: Báo cáo trung thực, không giấu findings
2. Confidentiality: Bảo mật thông tin khách hàng
3. Authorization: Chỉ test trong phạm vi được phép
4. Non-destructive: Không gây hại cho hệ thống
5. Responsible Disclosure: Báo cáo trước khi public
6. Documentation: Ghi chép đầy đủ mọi hành động
7. Professionalism: Maintain trust và reputation
Anti-patterns:
❌ Giữ lại backdoors sau khi test
❌ Exfiltrate data không cần thiết
❌ Test ngoài giờ/scope được phép
❌ Share findings với bên thứ ba
❌ Dùng findings cho mục đích cá nhân
6. Tổng kết
- Pentest: Mô phỏng tấn công có kiểm soát, tìm lỗ hổng + exploit + báo cáo
- Types: Black/Gray/White box, Network/Web/Cloud/Mobile
- ROE: Document scope, timeline, authorization, constraints
- Legal: ALWAYS có written authorization, tuân thủ pháp luật
- Ethics: Integrity, confidentiality, responsible disclosure
Bài tiếp theo sẽ tìm hiểu PTES — Penetration Testing Execution Standard.