Chuyển đến nội dung chính

Bài 12: PTES — Penetration Testing Execution Standard

Quy trình PTES 7 phase, từ Pre-engagement đến Reporting, mapping với OSSTMM và NIST SP 800-115.

🔒 DevSecOps — Bài 12 Bài 12: PTES — Penetration Testing Execution Standard

Performance Testing & Pentest: Quy trình Chuẩn Doanh nghiệp 2026

Phần 3: Pentest Foundations — Quy trình và Phương pháp luận

xdev.asia

1. PTES Overview

PTES (Penetration Testing Execution Standard) là tiêu chuẩn mở, được sử dụng rộng rãi trong ngành bảo mật, định nghĩa 7 giai đoạn cho một cuộc pentest chuyên nghiệp.

PTES 7 Phases:

┌──────────────────────────────────────────────────┐
│  Phase 1: Pre-engagement Interactions            │
│  ├── Scope definition                            │
│  ├── Rules of Engagement                         │
│  └── Authorization & NDA                         │
├──────────────────────────────────────────────────┤
│  Phase 2: Intelligence Gathering                 │
│  ├── OSINT (Open Source Intelligence)            │
│  ├── Footprinting & Fingerprinting               │
│  └── Social engineering reconnaissance           │
├──────────────────────────────────────────────────┤
│  Phase 3: Threat Modeling                        │
│  ├── Asset identification                        │
│  ├── Threat actor profiling                      │
│  └── Attack tree construction                    │
├──────────────────────────────────────────────────┤
│  Phase 4: Vulnerability Analysis                 │
│  ├── Automated scanning                          │
│  ├── Manual testing                              │
│  └── False positive validation                   │
├──────────────────────────────────────────────────┤
│  Phase 5: Exploitation                           │
│  ├── Vulnerability exploitation                  │
│  ├── Evasion techniques                          │
│  └── Proof of Concept development                │
├──────────────────────────────────────────────────┤
│  Phase 6: Post-Exploitation                      │
│  ├── Privilege escalation                        │
│  ├── Lateral movement                            │
│  ├── Data exfiltration (simulated)               │
│  └── Persistence analysis                        │
├──────────────────────────────────────────────────┤
│  Phase 7: Reporting                              │
│  ├── Executive Summary                           │
│  ├── Technical Report                            │
│  └── Remediation recommendations                 │
└──────────────────────────────────────────────────┘

2. Phase 1: Pre-engagement Interactions

Pre-engagement Checklist:

1. Scoping Questionnaire:
   □ Total number of IPs / hosts
   □ Number of web applications
   □ Authenticated / unauthenticated testing?
   □ Number of user roles to test
   □ API endpoints count
   □ Cloud infrastructure scope

2. Authorization:
   □ Get-Out-of-Jail letter
   □ NDA signed by both parties
   □ Emergency contacts exchanged
   □ Testing schedule agreed
   □ IP whitelist provided

3. Communication Plan:
   □ Encrypted channel setup (Signal, secure email)
   □ Status reporting frequency
   □ Critical finding notification SLA
   □ Point of contact for each side
# Pentest Authorization Letter Template

Date: 2026-04-01
Project: Annual Penetration Test - Example Corp

## Authorization
I, [CTO Name], hereby authorize [Pentest Company] to
perform penetration testing on:

### In-Scope Systems:
- 10.0.0.0/24 (Production Network)
- api.example.com (REST API)
- app.example.com (Web Application)
- mobile.example.com (Mobile Backend)
- AWS Account: 123456789012

### Testing Period:
From: 2026-04-01 08:00 UTC+7
To:   2026-04-14 18:00 UTC+7

### Restrictions:
- No Denial-of-Service attacks
- No physical access testing
- No social engineering
- Testing limited to business hours

### Emergency Contact:
Phone: +84-xxx-xxx-xxxx
Email: [email protected]

Signature: _______________

3. Phase 2: Intelligence Gathering

# --- Passive Reconnaissance ---

# Subdomain enumeration
subfinder -d example.com -all -o subdomains.txt
amass enum -passive -d example.com -o amass_subs.txt

# DNS records
dig example.com ANY +noall +answer
dig example.com MX +short
host -t txt example.com

# Certificate Transparency logs
curl -s "https://crt.sh/?q=%.example.com&output=json" \
  | jq -r '.[].name_value' | sort -u

# Wayback Machine
waybackurls example.com | sort -u > wayback.txt

# Google Dorks
# site:example.com filetype:pdf
# site:example.com inurl:admin
# site:example.com ext:sql | ext:env | ext:log

# Shodan
shodan search hostname:example.com

# --- Active Reconnaissance ---

# Port scanning (Nmap)
nmap -sV -sC -O -p- -oA full_scan example.com

# Service fingerprinting
nmap -sV --version-intensity 5 -p 80,443,8080 example.com

# Web technology detection
whatweb example.com
wappalyzer example.com  # browser extension

4. Phase 3: Threat Modeling

STRIDE Threat Model cho Web Application:

┌──────────────────────────────────────────┐
│           Web Application                │
├──────────────────────────────────────────┤
│ Threat         │ Attack Vector           │
├────────────────┼─────────────────────────┤
│ Spoofing       │ Session hijacking       │
│                │ Credential stuffing     │
├────────────────┼─────────────────────────┤
│ Tampering      │ SQL Injection           │
│                │ Parameter manipulation  │
├────────────────┼─────────────────────────┤
│ Repudiation    │ Log tampering           │
│                │ Missing audit trail     │
├────────────────┼─────────────────────────┤
│ Info Disclosure│ Error message leakage   │
│                │ Directory listing       │
├────────────────┼─────────────────────────┤
│ Denial of Svc  │ Resource exhaustion     │
│                │ ReDoS                   │
├────────────────┼─────────────────────────┤
│ Elev. Privilege│ IDOR                    │
│                │ Broken access control   │
└────────────────┴─────────────────────────┘

Attack Tree — Account Takeover:
  Root: Chiếm quyền tài khoản user
  ├── [OR] Brute-force login
  │   ├── [AND] Enumerate valid usernames
  │   └── [AND] No rate limiting
  ├── [OR] Password reset poisoning
  │   ├── [AND] Host header injection
  │   └── [AND] Predictable token
  ├── [OR] Session hijacking
  │   ├── [AND] XSS → steal cookie
  │   └── [AND] Cookie without HttpOnly
  └── [OR] OAuth misconfiguration
      ├── [AND] Open redirect in callback
      └── [AND] No state parameter

5. Phase 4: Vulnerability Analysis

# Automated scanning
# Nuclei — template-based scanner
nuclei -u https://example.com -t cves/ -t exposures/ -severity critical,high \
  -o nuclei_results.txt -stats

# Nessus CLI (tenable)
nessuscli scan --policy "Advanced Scan" --target 10.0.0.0/24

# OWASP ZAP automated scan
zap-cli quick-scan -s all -r report.html https://example.com

# nikto web scanner
nikto -h https://example.com -o nikto_results.html -Format html

# Manual testing checklist
# □ Authentication bypass
# □ Authorization checks (IDOR)
# □ Input validation (SQLi, XSS, SSRF)
# □ Business logic flaws
# □ Race conditions
# □ File upload restrictions
# □ API parameter pollution

6. Phase 5-6: Exploitation & Post-Exploitation

Exploitation Workflow:

  Vulnerability Found
        │
        ▼
  Verify Exploitability
        │
        ├── Can reproduce? ──No──▶ Document as unconfirmed
        │
        ▼ Yes
  Develop PoC (Proof of Concept)
        │
        ├── Minimal impact PoC
        ├── Screenshot / video evidence
        └── Document exact steps
        │
        ▼
  Assess Impact → CVSS v4.0 score
        │
        ▼
  Post-Exploitation (if authorized):
        ├── Privilege escalation attempt
        ├── Lateral movement mapping
        ├── Data access verification
        └── Persistence mechanism check
        │
        ▼
  Clean Up
        ├── Remove test accounts
        ├── Delete uploaded files
        ├── Restore modified configs
        └── Verify clean state

7. So sánh Pentest Frameworks

FrameworkScopeƯu điểmUse case
PTESGeneral pentestComprehensive, practicalEnterprise pentest
OSSTMM 3Security testingMetrics-based (RAV score)Compliance, audit
NIST SP 800-115Technical securityGovernment standardFederal / regulated
OWASP Testing Guide v5Web applicationWeb-focused, detailedWeb app pentest
MITRE ATT&CKAdversary TTPsReal-world mappingsRed team exercises
CRESTProfessional stdCertification-backedUK/intl pentest firms

8. Tổng kết

  • PTES: 7-phase standard — from pre-engagement to reporting
  • Pre-engagement: Authorization, scope, ROE, communication plan
  • Intelligence: Passive (OSINT) + Active (scanning) reconnaissance
  • Threat Modeling: STRIDE, Attack Trees, asset prioritization
  • Exploitation: Minimal impact PoC, evidence collection, clean up
  • Frameworks: PTES, OSSTMM, NIST, OWASP TG, MITRE ATT&CK

Bài tiếp theo sẽ phân tích chi tiết OWASP Top 10 (2025).