Defining the Testing Scope
A penetration test begins with a clearly defined scope of work. Before testing commences, you must obtain written authorization from the system owner and agree on a precise list of hosts, applications, and services subject to testing. Ambiguity in scope can lead to conflict and legal complications.
Documenting scope includes identifying target systems, authorized testing methods, time windows for testing, and points of contact for coordination. You must exclude systems outside the contract from testing and ensure all parties understand the limitations and risks involved.
- Obtain written authorization for testing activities
- Agree on the list of IP addresses and domains in scope
- Define testing schedule and permitted hours
- Identify critical systems with elevated security requirements
Applying Standardized Testing Methodology
The OWASP Web Security Testing Guide (WSTG) provides a structured approach to web application security assessment. Version 4.2 describes systematic methods for evaluating security, including reconnaissance, configuration review, authentication testing, and business logic analysis. Using a unified methodology ensures comprehensive coverage and reproducible results.
The methodology incorporates testing for vulnerabilities listed in OWASP Top 10, which represent the most critical risks to web applications. When applying these standards, the tester must adapt the methodology to the specific application, accounting for its architecture, technologies, and business functions.
- OWASP WSTG version 4.2 is available online and as PDF
- OWASP Top 10 defines priority areas for testing
- Methodology covers reconnaissance, scanning, and active testing phases
Reconnaissance and Information Gathering
Reconnaissance involves gathering information about the target system using open-source methods and authorized access. During this phase, the tester identifies the technology stack, software versions, server configuration, and domain information. This reduces blind attempts and makes testing more efficient.
Reconnaissance tools help identify open ports, web server versions, frameworks, and libraries in use. Version information is critical, as it enables identification of known vulnerabilities. However, all activities must remain within the agreed testing scope.
- Analyze HTTP response headers to determine software versions
- Identify application technology stacks
- Map network segments and open services
HTTP Protocol and Communication Analysis
HTTP remains the primary protocol for web application interaction. Understanding HTTP message structure, request methods (GET, POST, PUT, DELETE), and response codes is critical for vulnerability identification. HTTP headers contain important security information: Content-Security-Policy, X-Frame-Options, Strict-Transport-Security, and other protective directives.
During testing, analyze HTTP-based authentication mechanisms, cookie handling, redirections, and conditional requests. Special attention should be given to the presence or absence of required security headers that mitigate XSS, clickjacking, and sensitive data caching risks.
- Verify presence of Content-Security-Policy and other security headers
- Analyze cache management mechanisms
- Test handling of redirects and URL forwarding
Authentication and Session Management Testing
Authentication and session management are critical security components. Testing includes verification of password strength policies, proper implementation of account recovery mechanisms, and session cookie security. Check whether the application uses secure cookie flags (HttpOnly, Secure, SameSite) to prevent token theft via XSS and CSRF attacks.
Assess how effectively the application protects against credential brute-forcing, whether it logs unauthorized access attempts, and how properly it implements logout functionality. Session logic analysis includes verification of session ID uniqueness and unpredictability, expiration handling, and proper invalidation.
- Test resistance to credential brute-force attacks
- Verify cookie protection flags (HttpOnly, Secure, SameSite)
- Analyze session expiration and logout mechanisms
Code Injection Vulnerability Testing
Code injection encompasses SQL injection, cross-site scripting (XSS), operating system command injection, and other vectors. Testing requires systematic verification of all application entry points: query parameters, headers, cookies, and uploaded files. The tester must attempt to inject special characters and code constructs to identify insufficient input validation.
Most vulnerabilities in this class result from improper handling of user input. It is important to test both primary attack vectors and filter bypasses. Parameterized database queries and proper output encoding are standard protective measures requiring verification.
- Systematically test all input parameters
- Verify proper input validation and sanitization
- Analyze error handling for information disclosure
Results Documentation and Reporting
Documentation is an integral part of a tester's work. Each identified vulnerability must be described with reproduction steps, potential impact, and remediation recommendations. The report must be structured so that both security engineers and application developers can effectively use it.
Classifying vulnerabilities by severity (critical, high, medium, low) helps the client prioritize fixes. The report should include an executive summary, detailed description of each vulnerability with proof of concept, and recommendations for risk mitigation and development process improvements.
- Each vulnerability must be reproducible and documented
- Use standard severity classification system
- Include remediation recommendations in the report