Defining the Testing Scope

External penetration testing focuses on identifying vulnerabilities in web applications and infrastructure accessible from external networks. Before beginning work, you must clearly define the testing boundaries: which applications, domains, and IP addresses are included in the scope, and which are explicitly excluded. Documenting this scope agreement in the contract protects both the tester and the client organization.

Proper scope definition prevents unintended impact on systems outside the test parameters. Agree on testing windows, methodologies, and procedures for handling critical production systems. This includes emergency contact information and procedures for stopping tests if issues are detected in production environments.

    Information Gathering and Reconnaissance

    Reconnaissance is the first and critically important phase of a penetration test. During this phase, information is collected about the target system from open sources: domains, subdomains, IP addresses, technologies in use, and organizational personnel information. Tools are used to analyze DNS records, perform WHOIS queries, analyze web servers, and inspect applications.

    Passive reconnaissance does not require direct interaction with the target system and therefore avoids triggering alarms. However, authorization to conduct the assessment must still be maintained. During reconnaissance, potential attack entry points are identified that will later undergo active analysis.

      Vulnerability Assessment and Active Testing

      Following information gathering, active testing is conducted to identify known and potential vulnerabilities. According to the OWASP Web Security Testing Guide methodology, applications must be checked for security compliance and deficiencies in access controls, input validation, session management, and other security components are identified.

      Testing must cover typical attack vectors, including injections (SQL, command), cross-site scripting (XSS), security misconfiguration, and other categories from the OWASP Top 10. Each discovered defect is documented with specific location in code or configuration, reproduction method, and potential impact assessment.

        HTTP Communication and Security Headers Analysis

        Testing the security of HTTP protocol communication is an important component of penetration testing. The presence and correctness of security headers must be verified: Content-Security-Policy (CSP), X-Frame-Options, Strict-Transport-Security (HSTS), and others. Proper configuration of these headers prevents an entire class of attacks, including clickjacking and XSS.

        Analysis of HTTP sessions includes verification of cookie management, correct implementation of authentication, validation of session tokens, and logging. HTTPS usage is checked, protocol version (HTTP/2 is preferred), presence of CORS policy, and correctness of its configuration to prevent unauthorized access to resources.

          Vulnerability Demonstration

          After identifying vulnerabilities, demonstration (exploitation) is conducted in a controlled manner to confirm their reality and assess impact. This distinguishes penetration testing from simple vulnerability scanning. Demonstration must be minimally invasive and not cause harm to the system, merely proving the possibility of attack.

          For each critical vulnerability, developers receive step-by-step instructions for reproducing the issue, enabling them to correctly address the root cause. The tester documents all actions performed during demonstration to ensure transparency and enable verification of fixes.

            Results Documentation

            A quality penetration test report includes a summary of identified vulnerabilities, their classification by severity, description of each issue with attack technique details and impact. The report must contain remediation recommendations, including references to official guidelines and best practices from organizations such as OWASP.

            The report should include testing metrics: application coverage, tested components, methodologies, and tools used. Results should be organized logically with separation by vulnerability types and their security impact. It is recommended to provide both a technical summary for developers and an executive summary for management.

              Remediation Verification and Re-testing

              After receiving the report, the organization begins working on remediation of identified vulnerabilities. The penetration tester should collaborate with the development team to confirm the correctness of fixes. At this stage, re-testing is conducted where previously found vulnerabilities are checked again.

              It is important to ensure that fixes not only close the specific vulnerability but address its root cause, preventing similar issues from appearing elsewhere in the application. The final re-testing report should contain the status of each vulnerability and evidence of its remediation.

                Sources

                PENTEST.RED / RED JOURNAL