literature review on blockchain
1
Literature Review Name
Course Name
University
Abstract—In today’s time of technological advancement,
information is more vulnerable than ever before, and new
security threats are being raised every day. To secure any
system, it is imperative to evaluate all loopholes or
vulnerabilities present in that system through penetration tests
before a potential attacker could compromise any of them. This
paper provides an overview on penetration testing and its
benefits, discusses various penetration testing strategies,
considers different types of pen tests and also analyzes five
different methodologies that are available for carrying out a
penetration test and compares them on features such as scope,
planning, flexibility and documentation capabilities. It also
includes discussion regarding OWASP Top 10 vulnerabilities
list declared in 2017. Finally, this document mentions various
commercial and open source tools and frameworks that are
available for performing penetration tests.
Keywords—Penetration testing, OSSTMM (Open Source
Security Testing Methodology Manual), PTES (Penetration
Testing Execution Standard), ISSAF (Information Systems
Security Assessment Framework), OWASP, SQL Injection,
Cross-Site Scripting (XSS).
I. INTRODUCTION
A. What is Penetration Testing?
Penetration testing is a comprehensive way of testing an
organization’s complete computing base which consists of
hardware, software and people. This involves an active
analysis of the system for any potential vulnerabilities,
including poor or improper system configuration, hardware
and software flaws, and operational weaknesses in the
processes involved in the business [1]. In other words, it is a
process of identifying vulnerabilities or discovering
loopholes within a system before they could be used by any
potential hacker to exploit the system.
B. Benefits of Penetration Testing
There are several benefits of employing Penetration Testing
in an organization. Some of them are discussed below: [1]
1. Penetration testing provides a detailed view of potential
threats and risks faced by an organization and thereby
helps to safeguard it against any internal or external
attacks. 2. Penetration testing helps in shaping the information
security strategy by quickly and accurately identifying
the vulnerabilities 3. It provides organizations with irrefutable information
that could help them in meeting the auditing or
compliance requirements as per industry regulations. 4. It helps to avoid any financial loss that could occur to
an organization in case of non-compliance or a security
breach as it is better for an organization to proactively
maintain its security than to face extreme losses, both
to its brand equity and to its financial stability.
5. It creates heightened awareness of security’s
importance at all levels of the organization and thereby
increases the chance that the organization is better
prepared to avoid any security incident that could
impact its reputation and customer loyalty. 6. It evaluates the effectiveness of existing security
products and if results reveal the need of future
investment or upgrade of the existing security
technologies then this report acts as a proof and builds
a solid case for proposal of investment to the senior
management.
C. Organization of Paper
This paper is organized into following sections: Section I
introduces penetration testing and reviews its various
benefits. Section II discusses various penetration testing
strategies that are used in employing pen tests. Section III
focuses on the types of penetration tests that are usually
carried out. Section IV studies various methodologies such
as NIST SP 800-115, Open Source Security Testing
Methodology Manual (OSSTMM), Penetration Testing
Execution Standard (PTES), Information Systems Security
Assessment Framework (ISSAF) and OWASP Testing
Guide. Section V reviews OWASP Top 10 Vulnerabilities
and Section VI mentions various frameworks and tools
available for penetration tests.
Section Literature Reviewed
I [1]
II [2]
III [3]
IV [4] [5] [6] [7] [8] [9]
V [10] [11] [12] [13]
VI [14] [15] [16] [17] [18] [19] [20] [21]
[22] [23]
II. PENETRATION TESTING STRATEGIES
It is important to consider the strategy used while
determining scope and objective of penetration test. This
strategy can be based on two factors; based on the amount of
information available or based on specific objective to be
achieved.
Based on the amount of information available to the tester,
there are three penetration-testing strategies [2]:
2
A. Black box: In black box penetration testing, the testers have no idea about the test target. They have to figure out
the loopholes of the system on their own from scratch.
This is similar to the blind test strategy which simulates
the actions and procedures of a real attacker who has no
information concerning the test target.
B. White box: In white box penetration testing, the testers are provided with all the necessary information about the
test target. This strategy is referred as targeted testing
where the testing team and the organization work
together to do the test with all the information provided
to the tester prior to test.
C. Gray box: In this type of testing, testers are usually provided with partial or limited information about the
test target. Testers need to gather further information
before conducting the test.
Based on the specific objectives to be achieved, there are two
penetration testing strategies [2]:
D. External testing: External testing refers to any attacks on the test target using procedures performed from outside
the organization that owns the test target. The objective
of external testing is to address the ability of an outside
attacker to get access into the internal network as well as
to determine how far the attacker can go if the access is
gained.
E. Internal testing: Internal testing is performed from within the organization that owns the test target. This
strategy is useful for estimating the damage a disgruntled
employee could cause. Internal testing is centred on
understanding what could happen if the test target is
successfully penetrated by an authorized user with
standard access privileges.
III. TYPES OF PENETRATION TESTS
Penetration tests can be broadly divided into following
categories [3]:
A. Network Services: This type of testing involves discovering security weaknesses and vulnerabilities in
the network infrastructure of an organization. These tests
can be carried out remotely or locally at particular
business location. However, it is mandatory to utilize
both approaches in order to gather all the possible data.
This type of test involves testing of following network
areas:
• Firewall configuration testing
• Stateful analysis testing
• Firewall bypass testing
• DNS level attacks which include zone transfer
testing, switching or routing based testing or any
miscellaneous network parameter testing.
Other software modules that are examined during this
test are:
• SSH client/server tests.
• Network databases like MYSQL/SQL Server.
• Exchange or SMTP mail servers.
• FTP client/server tests.
B. Web Application: This type of testing involves discovering the security vulnerabilities or weaknesses in
a web-based application. It includes examination of
various components like ActiveX, Applets, Plug-ins,
Scriptlets. It is more intense, detailed and need
investment of large amount of time to accurately and
thoroughly test any web application. Moreover, as there
is a continuous increase in threats coming from web
applications, the ways to test them are also constantly
progressing.
C. Client Side: This type of test is intended to find any type of locally occurring security vulnerability on any
software on user’s workstation that can be exploited by
an attacker. There could be programs or applications
like Putty, Sniffers, Web browsers (Internet Explorer,
Google Chrome, Mozilla Firefox, Safari), content
creation software packages (MS Power Point,
Photoshop, Adobe page maker) and media players that
may be vulnerable to attacks, so they need to be tested.
D. Wireless: As the name suggests, this test involves examination of all the wireless devices that are used in an
organization. This includes items such as tablets, laptops,
notebooks, iPods, smartphones, etc. Apart from all these
gadgets, the penetration tester should also consider
preparing tests for the following:
• Wireless configuration protocols in order to
determine the protocols that are considered to be
“weak” in nature.
• Wireless access points in order to verify which
access points are “rogue”.
• Administrative credentials
Usually, such tests are performed at the client site
because the Pen Testing equipment has to connect with
the wireless system to expose its vulnerabilities.
E. Social Engineering: This type of test is carried out to verify the “Human Network” of an organization. It
involves attempts to obtain confidential or proprietary
information by deliberately tricking a company’s
employee to reveal any such confidential information.
This is usually split into following two categories:
• Remote testing: This involves tricking an employee
to reveal sensitive information via an electronic
means. This is often conducted by launching a
Phishing E-mail Campaign.
• Physical testing: This involves the use of a physical
means or presence to gather sensitive information.
This includes human handling tactics like Dumpster
Diving, Intimidation, Impersonation or convincing
phone calls, etc.
IV. METHODOLOGIES
The success of penetration testing depends on the underlying
methodology used and lack of a formal methodology could
lead to incomplete or inaccurate penetration test. There are
3
number of methodologies available some of which are
discussed below:
A. NIST Special Publication 800-115 Technical Guide to Information Security Testing and Assessment [4]
The methodology proposed by NIST mentions four phases
of penetration testing which are Planning, Discovery, Attack
and Reporting.
Fig. 1. Four-Stage Penetration Testing Methodology [4]
In planning phase, rules are identified, management
approval is finalized and documented, testing goals are set
and the system is analyzed to find the most interesting test
targets. The planning phase sets the groundwork for a
successful penetration test. No actual testing occurs in this
phase.
In discovery phase, testing includes two parts. The first part
is the start of actual testing, and covers information gathering
and scanning to gather information on the targeted network.
The second part includes vulnerability analysis which
involves comparing the services, applications, and operating
systems of scanned hosts against vulnerability databases (a
process that is automatic for vulnerability scanners) and the
tester’s own knowledge of vulnerabilities. Human testers
can use their own databases or public databases such as the
National Vulnerability Database (NVD) can be used to
identify vulnerabilities manually.
In attack phase, the tester validates that the found
vulnerabilities can be exploited. In this stage, additional
phases like “gaining access, escalating privileges, system
browsing, and installing additional tools” are also present.
In reporting phase, every result from the activities carried
out in the previous steps is reported. A final report is
generally developed at the end to describe identified
vulnerabilities, present a risk rating, and give guidance on
how to mitigate the discovered weaknesses.
B. Open Source Security Testing Methodology Manual (OSSTMM) [5] [6] [7] [8]
OSSTMM is an international standard methodology for
security testing, maintained by ISECOM (Institute for
Security and Open Methodologies). It starts the security test
with the establishment of a scope, which represents all
possible operational security environment for any interaction
with any asset. The scope consists of three channels:
• PHYSSEC (physical security channel)
• SPECSEC (spectrum security channel)
• COMSEC (communications security channel).
Channels are the means of interacting with assets. An asset
is what is valuable to the owner. The scope requires that all
the threats must be considered possible, even if not probable.
These three main channels are further divided into five sub-
channels which are as follows:
• Human: This includes all the human elements of
communications.
• Physical: This involves the substantial elements of
security where interaction requires physical effort to
manipulate assets.
• Wireless Communication: This comprises all the
electronic communications and signals which take place
over the EM spectrum.
• Data Networks: This involves all the electronic systems
and data networks where communications occur over
established cables and wired network lines.
• Telecommunication: This covers all the digital or analog
telecommunication networks where the communication
takes place over established telephone or telephone-like
network lines.
Further, OSSTMM describes seventeen modules to analyze
each of the sub-channels. So, the tester has to perform 85
(17*5=85) analyses before writing the final report.
Fig. 2. Seventeen Modules of OSSTMM Model [8]
This methodology discusses six different test types (Blind,
Double Blind, Gray Box, Double Gray Box, Tandem and
Reversal) based on the amount of information the tester
knows about the targets, what the target knows about the
tester or expects from the test, and the legitimacy of the test.
There are no tools indicated for the testing process but only
the information about the tasks to be executed is provided for
each channel. Finally, to measure both the thoroughness of
4
the test and the security of the target, use of this methodology
concludes with the Security Test Audit Report (STAR).
C. Penetration Testing Execution Standard (PTES) [9]
The PTES methodology defines seven main sections as the
basis for penetration test execution. These sections are as
follows:
1) Pre-engagement Interactions: This section defines the
testing scope which include many things like goal, target
specifications, test type, start and end dates, IP ranges
and domains, payment terms, rules of engagement and
so on. It also includes various set of general questions
that should be answered before a test begins,
2) Intelligence Gathering: This section involves
performing reconnaissance against a target to gather as
much information as possible which would be utilized
when penetrating the target during the vulnerability
assessment and exploitation phase.
3) Threat Modeling: The standard does not use a specific
model but it requires that the model used should be in
coordination with the organization being tested in terms
of representation of threats, capabilities and
qualifications. Additionally, it mentions that even in
case of a complete black-box situation where the tester
does not have any prior information on the organization,
the tester should create a threat model based on the
attacker’s view in combination with OSINT (Open
Source intelligence) related to the target organization.
4) Vulnerability Analysis: This section deals with the
detection of vulnerabilities of the target system which
could be leveraged by an attacker.
5) Exploitation: This section focuses solely on establishing
access to a system or resource by exploiting the
vulnerabilities found in last section. The main emphasis
here is to identify the main entry point into the
organization and to identify high value target assets.
6) Post Exploitation: The purpose of the post-exploitation
phase is to determine the value of the machine
compromised and to maintain control of the machine for
later use. The value of the machine is determined by the
sensitivity of the data stored on it and the machines
usefulness in further compromising the network.
7) Reporting: This section involves writing a final report
which has to be sent to the customer. This methodology
specifies that the report should be broken down into two
major sections (The Executive Summary and Technical
report) in order to communicate the objectives, methods
and results of the testing conducted to various audiences.
The purpose of the methodology is not to establish rigid
patterns for a penetration test. However, it discusses the
penetration testing step with a more technical approach by
giving specific recommendations and details. The
community of analysts and security professionals
responsible for creating the methodology suggest that the
guidelines for the security evaluation process of an
environment should be comprehensible for organizations.
Therefore, the technical guidelines help to define procedures
to follow throughout a Pentest, enabling the methodology to
provide a basic structure to initiate and conduct a security
test.
D. Information Systems Security Assessment Framework (ISSAF) [7] [8]
The Information Systems Security Assessment Framework
(ISSAF) is a penetration testing methodology developed by
Open Information Systems Security Group (OISSG). It is
designed to evaluate the security of networks, systems and
application controls. Its design is structured in three main
areas which are as follows:
• Planning and Preparation: This step includes setting up the test environment, testing tools, contracts and legal
aspects, definition of engagement team, deadlines,
requirements, and structure of the final reports.
• Assessment: This step is the core of the methodology, where the real penetration tests are carried out. It
includes nine steps that go through the practical
operations needed to identify and exploit
vulnerabilities. These steps are:
1) Information Gathering
2) Network Mapping
3) Vulnerability Identification
4) Penetration
5) Gaining Access & Privilege Escalation
6) Enumerating Further
7) Compromise Remote Users Sites
8) Maintaining Access
9) Covering Tracks.
• Reporting, Clean-up and Destroy Artifacts: In this phase, testers have to write a complete report at the end
and need to destroy artifacts built during the
Assessment phase.
Fig. 3. Information Systems Security Assessment Framework [8]
This methodology has a clear and very intuitive structure,
which guides the tester through the complicated assessment
steps. It is as comprehensive as OSSTMM and is more
detailed than NIST SP 800-115. However, the framework is
5
less flexible than the other methodologies and cannot easily
adapt to different kinds of IT environment. Moreover, the
reporting section is also poorly implemented and there is no
well-defined and accurate guidelines to develop final reports.
E. OWASP Testing Guide
OWASP has a methodology driven by the idea of making
secure software a reality, and therefore, the guidelines are
directed towards testing security for web applications. In
most software development organizations, security concerns
are not present in the development process. Therefore, this
methodology idealizes the use of security testing as a means
of awareness and is based on other projects provided by the
OWASP such as Code Review Guide and Development
Guide.
The methodology is divided into three main stages:
• The introductory stage: This deals with the
preconditions for testing web applications and also the
testing scope.
• The intermediate stage: This presents the OWASP
Testing Framework with its techniques and tasks that
are related to the different phases of the Software
Development Life Cycle;
• The conclusive stage: This describes how
vulnerabilities are tested by Code Review and
Penetration Testing.
Finally, after reviewing the methodologies individually, it is
important to compare these methodologies in order to
identify the fundamental features that a ‘good’ methodology
should possess. The methodologies would be compared on
below mentioned features: [6] [8]
Scope: The NIST, OSSTMM, PTES and ISSAF
methodologies are easily integrated and can be tailored to
applications and operating systems, databases, physical
security assessments, and web applications. However, the
OWASP Testing Guide model is precisely focused for web
applications and services. In this sense, the coverage of
OWASP methodology can represent a limitation.
Planning: A methodology should properly define the whole
set of requirements prior to the start of the test execution in
a security test. Things like “definition of phases,
prerequisites for each phase, tools to use in each phase,
expected outcomes” could be examples of planning support
feature. PTES is a methodology that provides this type of
feature. It describes, carefully, all the planning that must be
defined in order to initiate and conduct a security test. NIST
and OSSTMM do not focus on providing a very detailed
planning as they try to provide great flexibility.
Flexibility: It is important that the methodology provides a
structured way of dynamically integrating additions in the
initially defined plan thereby, leading to richer and more
specific, new plans. In this sense, even if a static definition
of plans and steps to be followed is a prime requirement, the
flexibility to include new items makes a methodology more
interesting. In this sense, the model provided by NIST allows
the testers to have greater dynamism throughout the test,
since they can consider and re-evaluate their artifacts in each
activity. In contrast, some methodologies, such as, ISSAF,
OSSTMM, and OWASP Testing Guide limit such flexibility
as they are more robust in treating execution scenarios.
Documentation: Finally, the documentation can also be
considered as a key feature of setting up a Penetration test.
All studied methodologies provide instructions regarding
documentation. However, PTES does not provide a complete
description on how to produce a documentation that contains
detailed explanations of each process and activity. For this
reason, it is the only model that does not fully fulfill this
feature.
V. OWASP TOP 10 VULNERABILITIES
According to NIST SP 800-30, vulnerability can be defined
as a flaw or weakness in system security procedures, design,
implementation, or internal controls that could be exercised
(accidentally triggered or intentionally exploited) and result
in a security breach or a violation of the system's security
policy.
OWASP (Open Web Application Security Project) is a
worldwide free and open community focused on improving
the security of application software. OWASP Top 10 is a
powerful awareness document for web application security.
It represents a broad consensus about the most critical
security risks to web applications. Below table shows the
Top 10 vulnerabilities declared by the OWASP in 2017 [10]
along with the common weakness enumeration (CWE)
associated [11].
Vulnerability CWE Rank
Injection CWE-1027 A1
Broken
Authentication
CWE-1028 A2
Sensitive Data
Exposure
CWE-1029 A3
XML External
Entities (XXE)
CWE-1030 A4
Broken Access
Control
CWE-1031 A5
Security
Misconfiguration
CWE-1032 A6
Cross-Site
Scripting (XSS)
CWE-1033 A7
Insecure
Deserialization
CWE-1034 A8
Using
Components
with Known
Vulnerabilities
CWE-1035 A9
Insufficient
Logging &
Monitoring
CWE-1036 A10
Fig. 4. OWASP TOP 10 VULNERABILITIES 2017 [10] [11]
Brief description of each of these vulnerabilities is discussed
below [10]:
i. Injection: Injection flaws, such as SQL, OS, and LDAP
injection, occur when an attacker supplies untrusted input
6
to a program. This input is then processed as part of a
command or query by the interpreter. Therefore, the
attacker’s hostile data can trick the interpreter into
executing unintended commands or accessing data
without proper authorization.
Among these injection attacks, SQL injection is the most
widespread. In this, an attacker could bypass
authentication, access, modify and delete data within a
database. In some cases, SQL Injection can even be used
to execute commands on the operating system,
potentially allowing an attacker to escalate to more
damaging attacks inside of a network that sits behind a
firewall.
SQL Injection can be classified into three major
categories – In-band SQLi, Inferential SQLi and Out-of-
band SQLi.
In-band SQLi (Classic SQLi): This is the most common
and easy-to-exploit among SQL Injection attacks. In-
band SQL Injection occurs when an attacker is able to use
the same communication channel to both launch the
attack as well as to gather results.
Inferential SQLi: It may take longer for an attacker to
exploit inferential SQLi than in-band SQLi as in this case
the attacker does not receive the results as quickly. In this
attack, the attacker is able to reconstruct the database
structure by sending payloads, observing the web
application’s response and the resulting behavior of the
database server.
Out-of-band SQLi: This is not very common as in order
to execute this attack the attacker needs to make sure that
certain features are enabled on the database server.
However, attacker try to carry out out-of-band SQLi only
when in-band and inferential SQLi cannot be carried out.
[10] [12]
ii. Broken Authentication: Authentication & session
management is a critical section of web application
security. However, application functions related to
authentication and session management are often
implemented incorrectly that allows attackers to
compromise critical information like passwords,
encryption-decryption keys, or session tokens or to
exploit other implementation flaws that permit an
attacker to assume other users' identity temporarily or
permanently. [10]
iii. Sensitive Data Exposure: As the name suggests,
sensitive data exposure occurs when the web applications
and APIs do not properly safeguard the sensitive
information such as PII, financial or healthcare data.
Attackers may steal or modify such weakly protected
data to conduct credit card fraud, identity theft, or other
crimes. It is also important to encrypt data at all times
whether at rest or in transit as sensitive data may be
compromised without extra protection when exchanged
with the browser. [10]
iv. XML External Entities (XXE): There are many older or
badly configured XML processors that evaluate external
entity references within XML documents. These external
entities can be used by the attackers to disclose internal
files using the file URI handler, internal file shares,
internal port scanning, remote code execution, and denial
of service attacks. [10]
v. Broken Access Control: Poor enforcement of restrictions
on what authenticated users are allowed to do permit
attackers to exploit such flaws and carry out unauthorized
functionality or access unauthorized data, such as other
users' accounts, view sensitive files, modify other users'
data or change access rights, etc. [10]
vi. Security Misconfiguration: This is the most frequently
seen issue and is usually caused by insecure default
configurations, incomplete or ad hoc configurations,
open cloud storage, misconfigured HTTP headers, and
verbose error messages containing sensitive information.
Therefore, it is imperative that all operating systems,
frameworks, libraries, and applications should not only
be securely configured, but also patched/upgraded in a
timely fashion. [10]
vii. Cross-Site Scripting (XSS): Cross-Site Scripting (XSS)
attacks are a type of injection, in which malicious scripts
are injected into trusted websites. XSS attacks occur
when the data enters a Web application through an
untrusted source or when the data is included in dynamic
content that is sent to a web user without being validated
for malicious content. XSS allows attackers to execute
scripts in the victim's browser which can hijack user
sessions, deface web sites, or redirect the user to
malicious sites. XSS attacks are categorized into
following categories:
Persistent/Stored XSS: In this type of XSS attack, the
injected malicious script is permanently stored on the
target server as an input string through message forum,
visitor log or comment field where the data is expected in
a text format. The victim then retrieves this malicious
script from the server when it requests the stored
information.
Reflected XSS/Non-Persistent: In this type of XSS attack,
the malicious code is injected in the client request that is
reflected off the web server. These attacks are delivered
to victims via an e-mail message or through a link on
some other website. When a user is deceived to click on
such malicious link, the injected code travels to the
vulnerable website, which then reflects the attack back to
the user’s browser.
DOM based XSS: DOM stands for document object
model. This is a client-side attack where the attack
payload is executed as a result of modifying the DOM
“environment” in the victim’s browser used by the
original client-side script, so that the client-side code runs
in an “unexpected” manner. [10] [13]
viii. Insecure Deserialization: This often leads to remote
code execution. Even if deserialization flaws do not result
in remote code execution, they can be used to perform
attacks, including replay attacks, injection attacks, and
privilege escalation attacks. [10]
7
ix. Using Components with Known Vulnerabilities: Components, such as libraries, frameworks, and other
software modules, run with the same privileges as the
application. If a vulnerable component is exploited, such
an attack can facilitate serious data loss or server
takeover. Applications and APIs using components with
known vulnerabilities may weaken application defenses
and enable various attacks and impacts. [10]
x. Insufficient Logging & Monitoring: Inadequate logs
and monitoring activities along with missing or
ineffective integration with incident response, permits
attackers to further attack systems, maintain persistence,
tamper, extract, or destroy data. Most breach studies
show that the time to detect a breach is more than 200
days and is usually detected by external parties rather
than being detected by internal processes or monitoring.
[10]
VI. FRAMEWORKS AND TOOLS
There are number of tools available for penetration testing
and each one of them is capable of doing different kind of
pen test. Below is the list of commonly used tools with brief
description of each tool. The in-depth discussion of these
tools is out of scope for this document.
• Metasploit: This is the most widespread and advanced
framework that can be used for pen-testing. It is based on
the concept of ‘exploit’ which is basically a code that can
provide access to the target system. If the exploit is
successful, it runs a ‘payload’, a code that performs
operations on a target machine, thus creating a perfect
framework for penetration testing. This tool includes
large database of various exploits and methods which
provides smart testing platform to penetration tester. It
can be used on web applications, networks, servers, etc.
It has a command-line and the GUI clickable interface
which works on Linux, Apple Mac OS X, and Microsoft
Windows. This is commercial product, however there are
few free limited trials available along with an open source
Metaspoilt framework. [14]
• Netsparker: It is a commercial, very accurate automated
scanner that identify vulnerabilities such as SQL
Injection and Cross-site Scripting in web applications
and web APIs. It uniquely verifies the identified
vulnerabilities proving that they are genuine and not just
false positives. It is available as a Windows software and
an online service. [15]
• Acunetix: It is also a commercial tool used for identifying
the vulnerabilities in web applications. It is capable of
detecting and reporting on over 4500 web application
vulnerabilities including all variants of SQL Injection
and XSS. It fully supports HTML5, JavaScript and
Single-page applications as well as Content management
systems. It also includes advanced manual tools for
penetration testers and integrates with popular Issue
Trackers and WAFs. [16]
• Burpsuite: Burp Suite is a widely used commercial web
application security testing software. Burpsuite comes in
two versions – Burp Suite Professional for hands-on
testers, and Burp Suite Enterprise Edition with scalable
automation and CI integration. This tool has multiple
features like coverage of over 100 generic vulnerabilities,
such as SQL injection and cross-site scripting (XSS),
with great performance against all vulnerabilities in the
OWASP top 10, cutting-edge web application crawler, a
full JavaScript analysis engine using a combination of
static (SAST) and dynamic (DAST) techniques for
detection of security vulnerabilities within client-side
JavaScript, such a DOM-based cross-site scripting and
detailed custom advisories for reported vulnerabilities.
[17]
• Nessus: Nessus, a product of Tenable is probably the
most popular vulnerability assessment tool in the market.
This tool works for different categories of security issues
such as Software Vulnerabilities, Misconfigurations,
Default Passwords, IPs scan, website scanning, and
compliance checks like PCI DSS Related Vulnerabilities
(compliance for the Payment Card Industry Data Security
Standard). It also gives a full detailed report according to
user-defined policies. [18]
• W3af: W3af (Web Application Attack and Audit
Framework) is an open source web application security
scanner developed using Python. The goal of W3af is to
secure web applications by finding and exploiting all web
application vulnerabilities. It offers both GUI as well as
command-line interface. W3af is divided into two main
parts, the core and the plug-ins. The core coordinates the
process and provides features which are then consumed
by the plug-ins to find the vulnerabilities and exploit
them. The plug-ins are connected and share information
with each other using a knowledge base. [19]
• Zed Attack Proxy (ZAP): The OWASP Zed Attack Proxy
(ZAP) is one of the world’s most popular free security
tools and is actively maintained by hundreds of
international volunteers. It automatically helps finds
security vulnerabilities in web applications while one is
developing and testing the applications. ZAP provides
automated scanners as well as a set of tools that allow to
find security vulnerabilities manually. It includes
features like proxy intercepting, scanning and spider to
crawl all the pages of web applications. [20]
• NMAP: Nmap ("Network Mapper") is a free and open
source utility for network discovery and security
auditing. It uses raw IP packets in different ways to
determine what hosts are available on the network, what
services (application name and version) those hosts are
8
offering, what operating systems (and OS versions) they
are running, what type of packet filters/firewalls are in
use, and dozens of other characteristics. Nmap is capable
of running on all major computer operating systems. [21]
• Kali Linux: Kali Linux is a free and an open source
Debian-based Linux distribution aimed at advanced
Penetration Testing and Security Auditing. Kali contains
several hundred tools aimed at various information
security tasks, such as Penetration Testing, Computer
Forensics and Security research. Kali Linux is developed,
funded and maintained by Offensive Security, a leading
information security training company. [22]
• Wireshark: Wireshark is world’s foremost and widely
used network packet analyzer. It allows analysis of
packets that are captured live in a network by deep
inspecting hundreds of protocols. It runs on Windows,
Linux, macOS, Solaris, FreeBSD, NetBSD, and many
others. It is the de facto standard across many commercial
and non-profit enterprises, government agencies, and
educational institutions. [23]
Tool Company Operating
System
License
Metasploit Rapid7 Cross-
platform
Framework-
Open Source
Community
/Express/Pro-
Commercial
Netsparker Netsparker Cross-
platform
Commercial
Acunetix Acunetix Cross-
platform
Commercial
Burpsuite PortSwigger Cross-
platform
Commercial
Nessus Tenable Cross-
platform
Commercial
W3af - Windows,
OS X,
Linux,
FreeBSD,
OpenBSD
Open Source
ZAP OWASP Linux,
Windows,
OS X
Open Source
NMAP - Cross-
platform
Open Source
Kali Linux Offensive
Security
Linux Open Source
Wireshark Wireshark Cross-
platform
Open Source
Fig. 5. Tools used for Penetration testing
VII. CONCLUSION AND FUTURE WORK
In conclusion, penetration testing is a comprehensive way of identifying vulnerabilities in a system. It offers benefits such as prevention of financial loss; compliance to industry regulators, customers and shareholders; preserving corporate image as well as proactive elimination of identified risks. The testers can choose the pen test strategy based on the amount of information available to them or on the basis of specific objective that needs to be achieved. This paper also discussed five different methodologies that are offered for penetration testing and compared them on the basis of certain features like scope, planning, flexibility and the documentation procedure. Additionally, this document also considered OWASP 2017 Top Ten which is a powerful web application security awareness document. Finally, this paper mentioned various commercial and open source tools that are available in the market to perform penetration tests.
During the literature review of this paper, it was observed that majority of the penetration test papers that were referred focused utmost on the web vulnerabilities, followed by vulnerabilities in the network environment. However, none of those papers mentioned penetration testing for IoT (Internet of Things) devices or mobile devices. Therefore, these fields could present the possibility of further study and research. Additionally, it is also essential to test and focus on common tools and frameworks available in the market in order to determine their performance and effectiveness under various test strategies.
VIII. REFERENCES
1. A. G. Bacudio, X. Yuan, B.-T. B. Chu and M. Jones, "An
Overview of Penetration Testing," International Journal of
Network Security & Its Applications (IJNSA), vol. 3, p. 20,
November 2011.
2. H. M. Z. A. Shebl and B. D. Beheshti, "A Study on Penetration
Testing Process and Tools," in IEEE Long Island Systems,
Applications and Technology Conference (LISAT), 2018.
3. R. Das, "Introduction to Pen Testing," Infosec, 04 September
2019. [Online]. Available:
https://resources.infosecinstitute.com/the-types-of-
penetration-testing/. [Accessed 11 November 2019].
4. K. Scarfone, M. Souppaya, A. Cody and A. Orebaugh,
"Technical Guide to Information Security Testing and
Assessment," NIST Special Publication 800-115, p. 80,
September 2008.
5. P. Herzog, "OSSTMM 3 – The Open Source Security Testing
Methodology Manual," ISECOM, no. 3.02, p. 209, December
2010.
6. D. D. Bertoglio and A. F. Zorzo, "Overview and open issues
on penetration test," Journal of the Brazilian Computer
Society, p. 16, 2017.
7. M. Caselli and F. Kargl, "A Security Assessment Methodology
for Critical Infrastructures," in International Conference on
Critical Information Infrastructures Security Springer, Cham,
2016.
8. M. Prandini and M. Ramilli, "Towards a practical and effective
security testing methodology," in The IEEE symposium on
Computers and Communications, Riccione, Italy , 2010.
9. "Penetration Testing Execution Standard," 16 August 2014.
[Online]. Available: http://www.pentest-
9
standard.org/index.php/Main_Page. [Accessed 12 November
2019].
10. The OWASP Foundation, "OWASP Top 10 - 2017," 2017.
[Online]. Available:
https://www.owasp.org/images/7/72/OWASP_Top_10-
2017_%28en%29.pdf.pdf. [Accessed 19 November 2019].
11. The MITRE Corporation, "CWE-Common Weakness
Enumeration," The MITRE Corporation, 19 September 2019.
[Online]. Available:
https://cwe.mitre.org/data/definitions/1026.html. [Accessed
19 November 2019].
12. Acunetix, "acunetix," 2019. [Online]. Available:
https://www.acunetix.com/blog/articles/injection-attacks/.
[Accessed 23 November 2019].
13. OWASP Foundation, "Cross-site Scripting," 05 June 2018.
[Online]. Available: https://www.owasp.org/index.php/Cross-
site_Scripting_(XSS). [Accessed 23 November 2019].
14. RAPID7, "metasploit," [Online]. Available:
https://www.metasploit.com/. [Accessed 23 November 2019].
15. Netsparker Ltd, "netsparker," 2019. [Online]. Available:
https://www.netsparker.com/?ab=v1. [Accessed 22
November 2019].
16. Acunetix, "acunetix," 2019. [Online]. Available:
https://www.acunetix.com/. [Accessed 23 November 2019].
17. PortSwigger Ltd., "PORTSWIGGER WEB SECURITY,"
2019. [Online]. Available: https://portswigger.net/burp.
[Accessed 23 November 2019].
18. tenable, "nessus-professional," 2019. [Online]. Available:
https://www.tenable.com/products/nessus/nessus-
professional. [Accessed 23 November 2019].
19. w3af.org, "w3af," 2013. [Online]. Available: http://w3af.org/.
[Accessed 23 November 2019].
20. OWASP Foundation, "OWASP Zed Attack Proxy Project," 21
June 2019. [Online]. Available:
https://www.owasp.org/index.php/OWASP_Zed_Attack_Pro
xy_Project#Justification. [Accessed 23 November 2019].
21. G. F. Lyon, "NMAP.ORG," [Online]. Available:
https://nmap.org/. [Accessed 22 November 2019].
22. Offensive Security, "Kali Docs Official Documentation,"
2019. [Online]. Available:
https://docs.kali.org/introduction/what-is-kali-linux.
[Accessed 23 November 2019].
23.. Wireshark Foundation, "Wireshark," [Online]. Available:
https://www.wireshark.org/. [Accessed 23 November 2019].