literature review on blockchain

profilemanpreetk
LiteratureReview.pdf

1

Literature Review Name

Course Name

Email

University

Abstract—In today’s time of technological advancement,

information is more vulnerable than ever before, and new

security threats are being raised every day. To secure any

system, it is imperative to evaluate all loopholes or

vulnerabilities present in that system through penetration tests

before a potential attacker could compromise any of them. This

paper provides an overview on penetration testing and its

benefits, discusses various penetration testing strategies,

considers different types of pen tests and also analyzes five

different methodologies that are available for carrying out a

penetration test and compares them on features such as scope,

planning, flexibility and documentation capabilities. It also

includes discussion regarding OWASP Top 10 vulnerabilities

list declared in 2017. Finally, this document mentions various

commercial and open source tools and frameworks that are

available for performing penetration tests.

Keywords—Penetration testing, OSSTMM (Open Source

Security Testing Methodology Manual), PTES (Penetration

Testing Execution Standard), ISSAF (Information Systems

Security Assessment Framework), OWASP, SQL Injection,

Cross-Site Scripting (XSS).

I. INTRODUCTION

A. What is Penetration Testing?

Penetration testing is a comprehensive way of testing an

organization’s complete computing base which consists of

hardware, software and people. This involves an active

analysis of the system for any potential vulnerabilities,

including poor or improper system configuration, hardware

and software flaws, and operational weaknesses in the

processes involved in the business [1]. In other words, it is a

process of identifying vulnerabilities or discovering

loopholes within a system before they could be used by any

potential hacker to exploit the system.

B. Benefits of Penetration Testing

There are several benefits of employing Penetration Testing

in an organization. Some of them are discussed below: [1]

1. Penetration testing provides a detailed view of potential

threats and risks faced by an organization and thereby

helps to safeguard it against any internal or external

attacks. 2. Penetration testing helps in shaping the information

security strategy by quickly and accurately identifying

the vulnerabilities 3. It provides organizations with irrefutable information

that could help them in meeting the auditing or

compliance requirements as per industry regulations. 4. It helps to avoid any financial loss that could occur to

an organization in case of non-compliance or a security

breach as it is better for an organization to proactively

maintain its security than to face extreme losses, both

to its brand equity and to its financial stability.

5. It creates heightened awareness of security’s

importance at all levels of the organization and thereby

increases the chance that the organization is better

prepared to avoid any security incident that could

impact its reputation and customer loyalty. 6. It evaluates the effectiveness of existing security

products and if results reveal the need of future

investment or upgrade of the existing security

technologies then this report acts as a proof and builds

a solid case for proposal of investment to the senior

management.

C. Organization of Paper

This paper is organized into following sections: Section I

introduces penetration testing and reviews its various

benefits. Section II discusses various penetration testing

strategies that are used in employing pen tests. Section III

focuses on the types of penetration tests that are usually

carried out. Section IV studies various methodologies such

as NIST SP 800-115, Open Source Security Testing

Methodology Manual (OSSTMM), Penetration Testing

Execution Standard (PTES), Information Systems Security

Assessment Framework (ISSAF) and OWASP Testing

Guide. Section V reviews OWASP Top 10 Vulnerabilities

and Section VI mentions various frameworks and tools

available for penetration tests.

Section Literature Reviewed

I [1]

II [2]

III [3]

IV [4] [5] [6] [7] [8] [9]

V [10] [11] [12] [13]

VI [14] [15] [16] [17] [18] [19] [20] [21]

[22] [23]

II. PENETRATION TESTING STRATEGIES

It is important to consider the strategy used while

determining scope and objective of penetration test. This

strategy can be based on two factors; based on the amount of

information available or based on specific objective to be

achieved.

Based on the amount of information available to the tester,

there are three penetration-testing strategies [2]:

2

A. Black box: In black box penetration testing, the testers have no idea about the test target. They have to figure out

the loopholes of the system on their own from scratch.

This is similar to the blind test strategy which simulates

the actions and procedures of a real attacker who has no

information concerning the test target.

B. White box: In white box penetration testing, the testers are provided with all the necessary information about the

test target. This strategy is referred as targeted testing

where the testing team and the organization work

together to do the test with all the information provided

to the tester prior to test.

C. Gray box: In this type of testing, testers are usually provided with partial or limited information about the

test target. Testers need to gather further information

before conducting the test.

Based on the specific objectives to be achieved, there are two

penetration testing strategies [2]:

D. External testing: External testing refers to any attacks on the test target using procedures performed from outside

the organization that owns the test target. The objective

of external testing is to address the ability of an outside

attacker to get access into the internal network as well as

to determine how far the attacker can go if the access is

gained.

E. Internal testing: Internal testing is performed from within the organization that owns the test target. This

strategy is useful for estimating the damage a disgruntled

employee could cause. Internal testing is centred on

understanding what could happen if the test target is

successfully penetrated by an authorized user with

standard access privileges.

III. TYPES OF PENETRATION TESTS

Penetration tests can be broadly divided into following

categories [3]:

A. Network Services: This type of testing involves discovering security weaknesses and vulnerabilities in

the network infrastructure of an organization. These tests

can be carried out remotely or locally at particular

business location. However, it is mandatory to utilize

both approaches in order to gather all the possible data.

This type of test involves testing of following network

areas:

• Firewall configuration testing

• Stateful analysis testing

• Firewall bypass testing

• DNS level attacks which include zone transfer

testing, switching or routing based testing or any

miscellaneous network parameter testing.

Other software modules that are examined during this

test are:

• SSH client/server tests.

• Network databases like MYSQL/SQL Server.

• Exchange or SMTP mail servers.

• FTP client/server tests.

B. Web Application: This type of testing involves discovering the security vulnerabilities or weaknesses in

a web-based application. It includes examination of

various components like ActiveX, Applets, Plug-ins,

Scriptlets. It is more intense, detailed and need

investment of large amount of time to accurately and

thoroughly test any web application. Moreover, as there

is a continuous increase in threats coming from web

applications, the ways to test them are also constantly

progressing.

C. Client Side: This type of test is intended to find any type of locally occurring security vulnerability on any

software on user’s workstation that can be exploited by

an attacker. There could be programs or applications

like Putty, Sniffers, Web browsers (Internet Explorer,

Google Chrome, Mozilla Firefox, Safari), content

creation software packages (MS Power Point,

Photoshop, Adobe page maker) and media players that

may be vulnerable to attacks, so they need to be tested.

D. Wireless: As the name suggests, this test involves examination of all the wireless devices that are used in an

organization. This includes items such as tablets, laptops,

notebooks, iPods, smartphones, etc. Apart from all these

gadgets, the penetration tester should also consider

preparing tests for the following:

• Wireless configuration protocols in order to

determine the protocols that are considered to be

“weak” in nature.

• Wireless access points in order to verify which

access points are “rogue”.

• Administrative credentials

Usually, such tests are performed at the client site

because the Pen Testing equipment has to connect with

the wireless system to expose its vulnerabilities.

E. Social Engineering: This type of test is carried out to verify the “Human Network” of an organization. It

involves attempts to obtain confidential or proprietary

information by deliberately tricking a company’s

employee to reveal any such confidential information.

This is usually split into following two categories:

• Remote testing: This involves tricking an employee

to reveal sensitive information via an electronic

means. This is often conducted by launching a

Phishing E-mail Campaign.

• Physical testing: This involves the use of a physical

means or presence to gather sensitive information.

This includes human handling tactics like Dumpster

Diving, Intimidation, Impersonation or convincing

phone calls, etc.

IV. METHODOLOGIES

The success of penetration testing depends on the underlying

methodology used and lack of a formal methodology could

lead to incomplete or inaccurate penetration test. There are

3

number of methodologies available some of which are

discussed below:

A. NIST Special Publication 800-115 Technical Guide to Information Security Testing and Assessment [4]

The methodology proposed by NIST mentions four phases

of penetration testing which are Planning, Discovery, Attack

and Reporting.

Fig. 1. Four-Stage Penetration Testing Methodology [4]

In planning phase, rules are identified, management

approval is finalized and documented, testing goals are set

and the system is analyzed to find the most interesting test

targets. The planning phase sets the groundwork for a

successful penetration test. No actual testing occurs in this

phase.

In discovery phase, testing includes two parts. The first part

is the start of actual testing, and covers information gathering

and scanning to gather information on the targeted network.

The second part includes vulnerability analysis which

involves comparing the services, applications, and operating

systems of scanned hosts against vulnerability databases (a

process that is automatic for vulnerability scanners) and the

tester’s own knowledge of vulnerabilities. Human testers

can use their own databases or public databases such as the

National Vulnerability Database (NVD) can be used to

identify vulnerabilities manually.

In attack phase, the tester validates that the found

vulnerabilities can be exploited. In this stage, additional

phases like “gaining access, escalating privileges, system

browsing, and installing additional tools” are also present.

In reporting phase, every result from the activities carried

out in the previous steps is reported. A final report is

generally developed at the end to describe identified

vulnerabilities, present a risk rating, and give guidance on

how to mitigate the discovered weaknesses.

B. Open Source Security Testing Methodology Manual (OSSTMM) [5] [6] [7] [8]

OSSTMM is an international standard methodology for

security testing, maintained by ISECOM (Institute for

Security and Open Methodologies). It starts the security test

with the establishment of a scope, which represents all

possible operational security environment for any interaction

with any asset. The scope consists of three channels:

• PHYSSEC (physical security channel)

• SPECSEC (spectrum security channel)

• COMSEC (communications security channel).

Channels are the means of interacting with assets. An asset

is what is valuable to the owner. The scope requires that all

the threats must be considered possible, even if not probable.

These three main channels are further divided into five sub-

channels which are as follows:

• Human: This includes all the human elements of

communications.

• Physical: This involves the substantial elements of

security where interaction requires physical effort to

manipulate assets.

• Wireless Communication: This comprises all the

electronic communications and signals which take place

over the EM spectrum.

• Data Networks: This involves all the electronic systems

and data networks where communications occur over

established cables and wired network lines.

• Telecommunication: This covers all the digital or analog

telecommunication networks where the communication

takes place over established telephone or telephone-like

network lines.

Further, OSSTMM describes seventeen modules to analyze

each of the sub-channels. So, the tester has to perform 85

(17*5=85) analyses before writing the final report.

Fig. 2. Seventeen Modules of OSSTMM Model [8]

This methodology discusses six different test types (Blind,

Double Blind, Gray Box, Double Gray Box, Tandem and

Reversal) based on the amount of information the tester

knows about the targets, what the target knows about the

tester or expects from the test, and the legitimacy of the test.

There are no tools indicated for the testing process but only

the information about the tasks to be executed is provided for

each channel. Finally, to measure both the thoroughness of

4

the test and the security of the target, use of this methodology

concludes with the Security Test Audit Report (STAR).

C. Penetration Testing Execution Standard (PTES) [9]

The PTES methodology defines seven main sections as the

basis for penetration test execution. These sections are as

follows:

1) Pre-engagement Interactions: This section defines the

testing scope which include many things like goal, target

specifications, test type, start and end dates, IP ranges

and domains, payment terms, rules of engagement and

so on. It also includes various set of general questions

that should be answered before a test begins,

2) Intelligence Gathering: This section involves

performing reconnaissance against a target to gather as

much information as possible which would be utilized

when penetrating the target during the vulnerability

assessment and exploitation phase.

3) Threat Modeling: The standard does not use a specific

model but it requires that the model used should be in

coordination with the organization being tested in terms

of representation of threats, capabilities and

qualifications. Additionally, it mentions that even in

case of a complete black-box situation where the tester

does not have any prior information on the organization,

the tester should create a threat model based on the

attacker’s view in combination with OSINT (Open

Source intelligence) related to the target organization.

4) Vulnerability Analysis: This section deals with the

detection of vulnerabilities of the target system which

could be leveraged by an attacker.

5) Exploitation: This section focuses solely on establishing

access to a system or resource by exploiting the

vulnerabilities found in last section. The main emphasis

here is to identify the main entry point into the

organization and to identify high value target assets.

6) Post Exploitation: The purpose of the post-exploitation

phase is to determine the value of the machine

compromised and to maintain control of the machine for

later use. The value of the machine is determined by the

sensitivity of the data stored on it and the machines

usefulness in further compromising the network.

7) Reporting: This section involves writing a final report

which has to be sent to the customer. This methodology

specifies that the report should be broken down into two

major sections (The Executive Summary and Technical

report) in order to communicate the objectives, methods

and results of the testing conducted to various audiences.

The purpose of the methodology is not to establish rigid

patterns for a penetration test. However, it discusses the

penetration testing step with a more technical approach by

giving specific recommendations and details. The

community of analysts and security professionals

responsible for creating the methodology suggest that the

guidelines for the security evaluation process of an

environment should be comprehensible for organizations.

Therefore, the technical guidelines help to define procedures

to follow throughout a Pentest, enabling the methodology to

provide a basic structure to initiate and conduct a security

test.

D. Information Systems Security Assessment Framework (ISSAF) [7] [8]

The Information Systems Security Assessment Framework

(ISSAF) is a penetration testing methodology developed by

Open Information Systems Security Group (OISSG). It is

designed to evaluate the security of networks, systems and

application controls. Its design is structured in three main

areas which are as follows:

• Planning and Preparation: This step includes setting up the test environment, testing tools, contracts and legal

aspects, definition of engagement team, deadlines,

requirements, and structure of the final reports.

• Assessment: This step is the core of the methodology, where the real penetration tests are carried out. It

includes nine steps that go through the practical

operations needed to identify and exploit

vulnerabilities. These steps are:

1) Information Gathering

2) Network Mapping

3) Vulnerability Identification

4) Penetration

5) Gaining Access & Privilege Escalation

6) Enumerating Further

7) Compromise Remote Users Sites

8) Maintaining Access

9) Covering Tracks.

• Reporting, Clean-up and Destroy Artifacts: In this phase, testers have to write a complete report at the end

and need to destroy artifacts built during the

Assessment phase.

Fig. 3. Information Systems Security Assessment Framework [8]

This methodology has a clear and very intuitive structure,

which guides the tester through the complicated assessment

steps. It is as comprehensive as OSSTMM and is more

detailed than NIST SP 800-115. However, the framework is

5

less flexible than the other methodologies and cannot easily

adapt to different kinds of IT environment. Moreover, the

reporting section is also poorly implemented and there is no

well-defined and accurate guidelines to develop final reports.

E. OWASP Testing Guide

OWASP has a methodology driven by the idea of making

secure software a reality, and therefore, the guidelines are

directed towards testing security for web applications. In

most software development organizations, security concerns

are not present in the development process. Therefore, this

methodology idealizes the use of security testing as a means

of awareness and is based on other projects provided by the

OWASP such as Code Review Guide and Development

Guide.

The methodology is divided into three main stages:

• The introductory stage: This deals with the

preconditions for testing web applications and also the

testing scope.

• The intermediate stage: This presents the OWASP

Testing Framework with its techniques and tasks that

are related to the different phases of the Software

Development Life Cycle;

• The conclusive stage: This describes how

vulnerabilities are tested by Code Review and

Penetration Testing.

Finally, after reviewing the methodologies individually, it is

important to compare these methodologies in order to

identify the fundamental features that a ‘good’ methodology

should possess. The methodologies would be compared on

below mentioned features: [6] [8]

Scope: The NIST, OSSTMM, PTES and ISSAF

methodologies are easily integrated and can be tailored to

applications and operating systems, databases, physical

security assessments, and web applications. However, the

OWASP Testing Guide model is precisely focused for web

applications and services. In this sense, the coverage of

OWASP methodology can represent a limitation.

Planning: A methodology should properly define the whole

set of requirements prior to the start of the test execution in

a security test. Things like “definition of phases,

prerequisites for each phase, tools to use in each phase,

expected outcomes” could be examples of planning support

feature. PTES is a methodology that provides this type of

feature. It describes, carefully, all the planning that must be

defined in order to initiate and conduct a security test. NIST

and OSSTMM do not focus on providing a very detailed

planning as they try to provide great flexibility.

Flexibility: It is important that the methodology provides a

structured way of dynamically integrating additions in the

initially defined plan thereby, leading to richer and more

specific, new plans. In this sense, even if a static definition

of plans and steps to be followed is a prime requirement, the

flexibility to include new items makes a methodology more

interesting. In this sense, the model provided by NIST allows

the testers to have greater dynamism throughout the test,

since they can consider and re-evaluate their artifacts in each

activity. In contrast, some methodologies, such as, ISSAF,

OSSTMM, and OWASP Testing Guide limit such flexibility

as they are more robust in treating execution scenarios.

Documentation: Finally, the documentation can also be

considered as a key feature of setting up a Penetration test.

All studied methodologies provide instructions regarding

documentation. However, PTES does not provide a complete

description on how to produce a documentation that contains

detailed explanations of each process and activity. For this

reason, it is the only model that does not fully fulfill this

feature.

V. OWASP TOP 10 VULNERABILITIES

According to NIST SP 800-30, vulnerability can be defined

as a flaw or weakness in system security procedures, design,

implementation, or internal controls that could be exercised

(accidentally triggered or intentionally exploited) and result

in a security breach or a violation of the system's security

policy.

OWASP (Open Web Application Security Project) is a

worldwide free and open community focused on improving

the security of application software. OWASP Top 10 is a

powerful awareness document for web application security.

It represents a broad consensus about the most critical

security risks to web applications. Below table shows the

Top 10 vulnerabilities declared by the OWASP in 2017 [10]

along with the common weakness enumeration (CWE)

associated [11].

Vulnerability CWE Rank

Injection CWE-1027 A1

Broken

Authentication

CWE-1028 A2

Sensitive Data

Exposure

CWE-1029 A3

XML External

Entities (XXE)

CWE-1030 A4

Broken Access

Control

CWE-1031 A5

Security

Misconfiguration

CWE-1032 A6

Cross-Site

Scripting (XSS)

CWE-1033 A7

Insecure

Deserialization

CWE-1034 A8

Using

Components

with Known

Vulnerabilities

CWE-1035 A9

Insufficient

Logging &

Monitoring

CWE-1036 A10

Fig. 4. OWASP TOP 10 VULNERABILITIES 2017 [10] [11]

Brief description of each of these vulnerabilities is discussed

below [10]:

i. Injection: Injection flaws, such as SQL, OS, and LDAP

injection, occur when an attacker supplies untrusted input

6

to a program. This input is then processed as part of a

command or query by the interpreter. Therefore, the

attacker’s hostile data can trick the interpreter into

executing unintended commands or accessing data

without proper authorization.

Among these injection attacks, SQL injection is the most

widespread. In this, an attacker could bypass

authentication, access, modify and delete data within a

database. In some cases, SQL Injection can even be used

to execute commands on the operating system,

potentially allowing an attacker to escalate to more

damaging attacks inside of a network that sits behind a

firewall.

SQL Injection can be classified into three major

categories – In-band SQLi, Inferential SQLi and Out-of-

band SQLi.

In-band SQLi (Classic SQLi): This is the most common

and easy-to-exploit among SQL Injection attacks. In-

band SQL Injection occurs when an attacker is able to use

the same communication channel to both launch the

attack as well as to gather results.

Inferential SQLi: It may take longer for an attacker to

exploit inferential SQLi than in-band SQLi as in this case

the attacker does not receive the results as quickly. In this

attack, the attacker is able to reconstruct the database

structure by sending payloads, observing the web

application’s response and the resulting behavior of the

database server.

Out-of-band SQLi: This is not very common as in order

to execute this attack the attacker needs to make sure that

certain features are enabled on the database server.

However, attacker try to carry out out-of-band SQLi only

when in-band and inferential SQLi cannot be carried out.

[10] [12]

ii. Broken Authentication: Authentication & session

management is a critical section of web application

security. However, application functions related to

authentication and session management are often

implemented incorrectly that allows attackers to

compromise critical information like passwords,

encryption-decryption keys, or session tokens or to

exploit other implementation flaws that permit an

attacker to assume other users' identity temporarily or

permanently. [10]

iii. Sensitive Data Exposure: As the name suggests,

sensitive data exposure occurs when the web applications

and APIs do not properly safeguard the sensitive

information such as PII, financial or healthcare data.

Attackers may steal or modify such weakly protected

data to conduct credit card fraud, identity theft, or other

crimes. It is also important to encrypt data at all times

whether at rest or in transit as sensitive data may be

compromised without extra protection when exchanged

with the browser. [10]

iv. XML External Entities (XXE): There are many older or

badly configured XML processors that evaluate external

entity references within XML documents. These external

entities can be used by the attackers to disclose internal

files using the file URI handler, internal file shares,

internal port scanning, remote code execution, and denial

of service attacks. [10]

v. Broken Access Control: Poor enforcement of restrictions

on what authenticated users are allowed to do permit

attackers to exploit such flaws and carry out unauthorized

functionality or access unauthorized data, such as other

users' accounts, view sensitive files, modify other users'

data or change access rights, etc. [10]

vi. Security Misconfiguration: This is the most frequently

seen issue and is usually caused by insecure default

configurations, incomplete or ad hoc configurations,

open cloud storage, misconfigured HTTP headers, and

verbose error messages containing sensitive information.

Therefore, it is imperative that all operating systems,

frameworks, libraries, and applications should not only

be securely configured, but also patched/upgraded in a

timely fashion. [10]

vii. Cross-Site Scripting (XSS): Cross-Site Scripting (XSS)

attacks are a type of injection, in which malicious scripts

are injected into trusted websites. XSS attacks occur

when the data enters a Web application through an

untrusted source or when the data is included in dynamic

content that is sent to a web user without being validated

for malicious content. XSS allows attackers to execute

scripts in the victim's browser which can hijack user

sessions, deface web sites, or redirect the user to

malicious sites. XSS attacks are categorized into

following categories:

Persistent/Stored XSS: In this type of XSS attack, the

injected malicious script is permanently stored on the

target server as an input string through message forum,

visitor log or comment field where the data is expected in

a text format. The victim then retrieves this malicious

script from the server when it requests the stored

information.

Reflected XSS/Non-Persistent: In this type of XSS attack,

the malicious code is injected in the client request that is

reflected off the web server. These attacks are delivered

to victims via an e-mail message or through a link on

some other website. When a user is deceived to click on

such malicious link, the injected code travels to the

vulnerable website, which then reflects the attack back to

the user’s browser.

DOM based XSS: DOM stands for document object

model. This is a client-side attack where the attack

payload is executed as a result of modifying the DOM

“environment” in the victim’s browser used by the

original client-side script, so that the client-side code runs

in an “unexpected” manner. [10] [13]

viii. Insecure Deserialization: This often leads to remote

code execution. Even if deserialization flaws do not result

in remote code execution, they can be used to perform

attacks, including replay attacks, injection attacks, and

privilege escalation attacks. [10]

7

ix. Using Components with Known Vulnerabilities: Components, such as libraries, frameworks, and other

software modules, run with the same privileges as the

application. If a vulnerable component is exploited, such

an attack can facilitate serious data loss or server

takeover. Applications and APIs using components with

known vulnerabilities may weaken application defenses

and enable various attacks and impacts. [10]

x. Insufficient Logging & Monitoring: Inadequate logs

and monitoring activities along with missing or

ineffective integration with incident response, permits

attackers to further attack systems, maintain persistence,

tamper, extract, or destroy data. Most breach studies

show that the time to detect a breach is more than 200

days and is usually detected by external parties rather

than being detected by internal processes or monitoring.

[10]

VI. FRAMEWORKS AND TOOLS

There are number of tools available for penetration testing

and each one of them is capable of doing different kind of

pen test. Below is the list of commonly used tools with brief

description of each tool. The in-depth discussion of these

tools is out of scope for this document.

• Metasploit: This is the most widespread and advanced

framework that can be used for pen-testing. It is based on

the concept of ‘exploit’ which is basically a code that can

provide access to the target system. If the exploit is

successful, it runs a ‘payload’, a code that performs

operations on a target machine, thus creating a perfect

framework for penetration testing. This tool includes

large database of various exploits and methods which

provides smart testing platform to penetration tester. It

can be used on web applications, networks, servers, etc.

It has a command-line and the GUI clickable interface

which works on Linux, Apple Mac OS X, and Microsoft

Windows. This is commercial product, however there are

few free limited trials available along with an open source

Metaspoilt framework. [14]

• Netsparker: It is a commercial, very accurate automated

scanner that identify vulnerabilities such as SQL

Injection and Cross-site Scripting in web applications

and web APIs. It uniquely verifies the identified

vulnerabilities proving that they are genuine and not just

false positives. It is available as a Windows software and

an online service. [15]

• Acunetix: It is also a commercial tool used for identifying

the vulnerabilities in web applications. It is capable of

detecting and reporting on over 4500 web application

vulnerabilities including all variants of SQL Injection

and XSS. It fully supports HTML5, JavaScript and

Single-page applications as well as Content management

systems. It also includes advanced manual tools for

penetration testers and integrates with popular Issue

Trackers and WAFs. [16]

• Burpsuite: Burp Suite is a widely used commercial web

application security testing software. Burpsuite comes in

two versions – Burp Suite Professional for hands-on

testers, and Burp Suite Enterprise Edition with scalable

automation and CI integration. This tool has multiple

features like coverage of over 100 generic vulnerabilities,

such as SQL injection and cross-site scripting (XSS),

with great performance against all vulnerabilities in the

OWASP top 10, cutting-edge web application crawler, a

full JavaScript analysis engine using a combination of

static (SAST) and dynamic (DAST) techniques for

detection of security vulnerabilities within client-side

JavaScript, such a DOM-based cross-site scripting and

detailed custom advisories for reported vulnerabilities.

[17]

• Nessus: Nessus, a product of Tenable is probably the

most popular vulnerability assessment tool in the market.

This tool works for different categories of security issues

such as Software Vulnerabilities, Misconfigurations,

Default Passwords, IPs scan, website scanning, and

compliance checks like PCI DSS Related Vulnerabilities

(compliance for the Payment Card Industry Data Security

Standard). It also gives a full detailed report according to

user-defined policies. [18]

• W3af: W3af (Web Application Attack and Audit

Framework) is an open source web application security

scanner developed using Python. The goal of W3af is to

secure web applications by finding and exploiting all web

application vulnerabilities. It offers both GUI as well as

command-line interface. W3af is divided into two main

parts, the core and the plug-ins. The core coordinates the

process and provides features which are then consumed

by the plug-ins to find the vulnerabilities and exploit

them. The plug-ins are connected and share information

with each other using a knowledge base. [19]

• Zed Attack Proxy (ZAP): The OWASP Zed Attack Proxy

(ZAP) is one of the world’s most popular free security

tools and is actively maintained by hundreds of

international volunteers. It automatically helps finds

security vulnerabilities in web applications while one is

developing and testing the applications. ZAP provides

automated scanners as well as a set of tools that allow to

find security vulnerabilities manually. It includes

features like proxy intercepting, scanning and spider to

crawl all the pages of web applications. [20]

• NMAP: Nmap ("Network Mapper") is a free and open

source utility for network discovery and security

auditing. It uses raw IP packets in different ways to

determine what hosts are available on the network, what

services (application name and version) those hosts are

8

offering, what operating systems (and OS versions) they

are running, what type of packet filters/firewalls are in

use, and dozens of other characteristics. Nmap is capable

of running on all major computer operating systems. [21]

• Kali Linux: Kali Linux is a free and an open source

Debian-based Linux distribution aimed at advanced

Penetration Testing and Security Auditing. Kali contains

several hundred tools aimed at various information

security tasks, such as Penetration Testing, Computer

Forensics and Security research. Kali Linux is developed,

funded and maintained by Offensive Security, a leading

information security training company. [22]

• Wireshark: Wireshark is world’s foremost and widely

used network packet analyzer. It allows analysis of

packets that are captured live in a network by deep

inspecting hundreds of protocols. It runs on Windows,

Linux, macOS, Solaris, FreeBSD, NetBSD, and many

others. It is the de facto standard across many commercial

and non-profit enterprises, government agencies, and

educational institutions. [23]

Tool Company Operating

System

License

Metasploit Rapid7 Cross-

platform

Framework-

Open Source

Community

/Express/Pro-

Commercial

Netsparker Netsparker Cross-

platform

Commercial

Acunetix Acunetix Cross-

platform

Commercial

Burpsuite PortSwigger Cross-

platform

Commercial

Nessus Tenable Cross-

platform

Commercial

W3af - Windows,

OS X,

Linux,

FreeBSD,

OpenBSD

Open Source

ZAP OWASP Linux,

Windows,

OS X

Open Source

NMAP - Cross-

platform

Open Source

Kali Linux Offensive

Security

Linux Open Source

Wireshark Wireshark Cross-

platform

Open Source

Fig. 5. Tools used for Penetration testing

VII. CONCLUSION AND FUTURE WORK

In conclusion, penetration testing is a comprehensive way of identifying vulnerabilities in a system. It offers benefits such as prevention of financial loss; compliance to industry regulators, customers and shareholders; preserving corporate image as well as proactive elimination of identified risks. The testers can choose the pen test strategy based on the amount of information available to them or on the basis of specific objective that needs to be achieved. This paper also discussed five different methodologies that are offered for penetration testing and compared them on the basis of certain features like scope, planning, flexibility and the documentation procedure. Additionally, this document also considered OWASP 2017 Top Ten which is a powerful web application security awareness document. Finally, this paper mentioned various commercial and open source tools that are available in the market to perform penetration tests.

During the literature review of this paper, it was observed that majority of the penetration test papers that were referred focused utmost on the web vulnerabilities, followed by vulnerabilities in the network environment. However, none of those papers mentioned penetration testing for IoT (Internet of Things) devices or mobile devices. Therefore, these fields could present the possibility of further study and research. Additionally, it is also essential to test and focus on common tools and frameworks available in the market in order to determine their performance and effectiveness under various test strategies.

VIII. REFERENCES

1. A. G. Bacudio, X. Yuan, B.-T. B. Chu and M. Jones, "An

Overview of Penetration Testing," International Journal of

Network Security & Its Applications (IJNSA), vol. 3, p. 20,

November 2011.

2. H. M. Z. A. Shebl and B. D. Beheshti, "A Study on Penetration

Testing Process and Tools," in IEEE Long Island Systems,

Applications and Technology Conference (LISAT), 2018.

3. R. Das, "Introduction to Pen Testing," Infosec, 04 September

2019. [Online]. Available:

https://resources.infosecinstitute.com/the-types-of-

penetration-testing/. [Accessed 11 November 2019].

4. K. Scarfone, M. Souppaya, A. Cody and A. Orebaugh,

"Technical Guide to Information Security Testing and

Assessment," NIST Special Publication 800-115, p. 80,

September 2008.

5. P. Herzog, "OSSTMM 3 – The Open Source Security Testing

Methodology Manual," ISECOM, no. 3.02, p. 209, December

2010.

6. D. D. Bertoglio and A. F. Zorzo, "Overview and open issues

on penetration test," Journal of the Brazilian Computer

Society, p. 16, 2017.

7. M. Caselli and F. Kargl, "A Security Assessment Methodology

for Critical Infrastructures," in International Conference on

Critical Information Infrastructures Security Springer, Cham,

2016.

8. M. Prandini and M. Ramilli, "Towards a practical and effective

security testing methodology," in The IEEE symposium on

Computers and Communications, Riccione, Italy , 2010.

9. "Penetration Testing Execution Standard," 16 August 2014.

[Online]. Available: http://www.pentest-

9

standard.org/index.php/Main_Page. [Accessed 12 November

2019].

10. The OWASP Foundation, "OWASP Top 10 - 2017," 2017.

[Online]. Available:

https://www.owasp.org/images/7/72/OWASP_Top_10-

2017_%28en%29.pdf.pdf. [Accessed 19 November 2019].

11. The MITRE Corporation, "CWE-Common Weakness

Enumeration," The MITRE Corporation, 19 September 2019.

[Online]. Available:

https://cwe.mitre.org/data/definitions/1026.html. [Accessed

19 November 2019].

12. Acunetix, "acunetix," 2019. [Online]. Available:

https://www.acunetix.com/blog/articles/injection-attacks/.

[Accessed 23 November 2019].

13. OWASP Foundation, "Cross-site Scripting," 05 June 2018.

[Online]. Available: https://www.owasp.org/index.php/Cross-

site_Scripting_(XSS). [Accessed 23 November 2019].

14. RAPID7, "metasploit," [Online]. Available:

https://www.metasploit.com/. [Accessed 23 November 2019].

15. Netsparker Ltd, "netsparker," 2019. [Online]. Available:

https://www.netsparker.com/?ab=v1. [Accessed 22

November 2019].

16. Acunetix, "acunetix," 2019. [Online]. Available:

https://www.acunetix.com/. [Accessed 23 November 2019].

17. PortSwigger Ltd., "PORTSWIGGER WEB SECURITY,"

2019. [Online]. Available: https://portswigger.net/burp.

[Accessed 23 November 2019].

18. tenable, "nessus-professional," 2019. [Online]. Available:

https://www.tenable.com/products/nessus/nessus-

professional. [Accessed 23 November 2019].

19. w3af.org, "w3af," 2013. [Online]. Available: http://w3af.org/.

[Accessed 23 November 2019].

20. OWASP Foundation, "OWASP Zed Attack Proxy Project," 21

June 2019. [Online]. Available:

https://www.owasp.org/index.php/OWASP_Zed_Attack_Pro

xy_Project#Justification. [Accessed 23 November 2019].

21. G. F. Lyon, "NMAP.ORG," [Online]. Available:

https://nmap.org/. [Accessed 22 November 2019].

22. Offensive Security, "Kali Docs Official Documentation,"

2019. [Online]. Available:

https://docs.kali.org/introduction/what-is-kali-linux.

[Accessed 23 November 2019].

23.. Wireshark Foundation, "Wireshark," [Online]. Available:

https://www.wireshark.org/. [Accessed 23 November 2019].