Defining Scope and Preparing for Penetration Testing

Before beginning a penetration test, clearly define the scope: which domains, IP addresses, functions, and components of the application are included in testing. Written authorization from the owner or responsible party is critical for legitimacy of the work. Documenting preliminary agreements protects both parties and ensures transparency during execution. Establishing clear rules of engagement prevents misunderstandings and provides legal protection.

Preparation includes gathering information about the application's technology stack, entry points such as login forms, API endpoints, and file upload mechanisms, as well as authentication mechanisms. Creating test accounts with various privilege levels enables access control verification. Using a separate isolated environment for testing prevents impact on production systems and allows safe exploitation of vulnerabilities.

    Critical Vulnerability Categories from OWASP Top 10

    The OWASP Top 10 defines the most critical risk categories for web applications. Testing must systematically cover these areas, starting with the most common: injections (SQL, command, LDAP), authentication bypass, sensitive data exposure, XML External Entity (XXE), broken access control, security misconfiguration, cross-site scripting (XSS), insecure deserialization, use of components with known vulnerabilities, and insufficient logging. Each category requires specific testing techniques and understanding of underlying technologies.

    For example, SQL injection testing uses various database syntaxes and operates against supported databases with different escape mechanisms. XSS testing covers DOM vectors, reflected vectors, and stored vectors with context-specific payloads. Access control testing attempts resource access belonging to other users and privilege escalation scenarios. Systematic coverage of OWASP Top 10 categories significantly reduces the risk of missing critical vulnerabilities during assessment.

      Standardized Testing Methodology: OWASP Web Security Testing Guide

      The OWASP Web Security Testing Guide (WSTG) provides a structured approach to security testing. The methodology divides the process into phases: information gathering, configuration and deployment management, identity management, authentication testing, authorization testing, session management, input validation, business logic testing, file upload testing, error handling verification, and logging assessment. For each phase, WSTG defines specific tests with detailed procedures and expected outcomes.

      During information gathering, technologies and frameworks are identified through HTTP header analysis, source code examination, and metadata inspection. Configuration assessment includes evaluation of web server security settings, SSL/TLS configuration, and availability of unsafe HTTP methods. This systematic approach reduces the risk of missing vulnerabilities. The structured methodology ensures consistency across multiple testers and comprehensive coverage of the application.

        Injection Testing and Input Validation Assessment

        Injections remain among the most dangerous vulnerability categories. Testing includes verification of all entry points: URL parameters, POST request bodies, HTTP headers, and cookies. SQL injection testing uses delimiter characters (single quote, double quote, semicolon), logical operators (OR 1=1), and UNION queries to reveal sensitive data. Database error messages often leak information about structure, aiding an attacker's understanding.

        XML injection and XXE attacks are tested by analyzing XML input processing, including external entity usage for accessing local files or performing SSRF attacks. Command injection testing uses shell special characters (semicolon, pipe, ampersand) when user input is passed to system commands. Effective testing requires understanding the syntax of the relevant technology (PHP, Python, Java) and available escaping mechanisms. Testing should include both known and novel injection vectors.

          Authentication, Authorization, and Session Management Testing

          Authentication mechanism testing includes verification for weak password policies, absence of multi-factor authentication, vulnerabilities in password recovery processes, and session timeout implementation. HTTP response headers are analyzed, particularly Set-Cookie headers, for missing HttpOnly, Secure, and SameSite flags. Attempts to intercept session tokens, reuse, or predict session identifiers reveal critical vulnerabilities. Testing also covers authentication bypass through direct access to protected resources or manipulation of authentication parameters.

          Authorization testing requires validation with different user roles and privilege levels. Horizontal privilege escalation is tested by attempting to access resources belonging to other users through identifier modification in URLs or request parameters. Vertical privilege escalation testing checks whether ordinary users can perform administrative functions. Session management analysis includes evaluation of session lifetime, logout mechanisms, and protection against session fixation attacks through secure session identifier generation and handling.

            Output Encoding Testing and Cross-Site Scripting (XSS)

            Cross-site scripting (XSS) is tested by injecting JavaScript code at entry points and observing execution. Reflected XSS is tested by transmitting a payload in URL parameters and analyzing the HTML response for unencoded input. Stored XSS is tested by uploading data with a payload and verifying its display for other users, demonstrating persistence. DOM-based XSS requires analysis of JavaScript code and DOM manipulation methods like innerHTML and eval, which may unsafely process user-controlled data.

            Different payloads are used for each vector based on context: HTML tag context, attribute context, JavaScript string context, and URL context. Typical payloads include alert boxes for confirming execution, demonstrating the ability to steal cookies, perform redirects, or modify page content. Verification of Content Security Policy (CSP) headers indicates additional protection against XSS attacks. Testing includes both simple vector detection and advanced payloads that bypass common security filters.

              Documentation, Analysis, and Reporting of Findings

              Each discovered vulnerability is documented with OWASP Top 10 classification, severity level (Critical, High, Medium, Low), problem description, reproduction steps, and proof-of-concept evidence. Distinguishing true vulnerabilities from false positives is critical for report quality. Remediation recommendations are provided for each finding with priority based on assessed risk. Clear communication of technical details enables development teams to understand and fix issues effectively.

              The final report includes executive summary, statistics by category and severity level, detailed vulnerability descriptions with context, testing methodology, and timeframe of work. Interaction with the development team during testing helps clarify context and validate discovered issues. Post-remediation retesting confirms the effectiveness of implemented security measures. Comprehensive documentation serves as both proof of work and reference for future security assessments and improvement efforts.

                Sources

                PENTEST.RED / RED JOURNAL