Scope Definition and Testing Objectives

Penetration testing is an authorized attempt to discover vulnerabilities in a web application by simulating attacker behaviour. Before commencing, clearly define the target system, permitted attack methods, and timeframe. GOST requires documentation of a testing agreement that specifies objectives, boundaries, and obligations of all parties involved in the engagement.

During the planning phase, identify critical application components, sensitive data assets, and functions requiring heightened protection. Coordinate which techniques—social engineering, port scanning, and other methods—are permissible. Documenting the scope protects both the organization and the security professional from legal complications.

  • Written authorization from all stakeholders before testing begins
  • Clear definition of data criticality and acceptable impact levels
  • Established timeline that minimizes disruption to production systems

Reconnaissance and Information Gathering

The first phase involves passive and active collection of information about the target application. Passive reconnaissance examines public sources, WHOIS data, DNS records, and search engine results without placing direct load on the target. Active reconnaissance makes requests to the application servers to identify software versions, application structure, and underlying technologies.

Information gathering results in documented identification of hosts, running services, software versions, and observable configuration patterns. This foundation enables planning of targeted attacks. GOST requires recording all discovered information in the testing protocol, including the method and timestamp of discovery.

  • Analysis of DNS and WHOIS information
  • Port scanning and service enumeration
  • Identification of the application technology stack

Vulnerability Assessment and Risk Analysis

After reconnaissance, systematic analysis identifies potential vulnerabilities. This process includes testing for known attack classes aligned with OWASP Top 10 standards and vulnerabilities specific to the application under test. The specialist uses both automated scanning tools and manual review of critical functions, as automated scanners cannot detect all vulnerability classes.

Each discovered vulnerability is evaluated using criteria: data sensitivity, accessibility to unauthorized users, required skill level for exploitation, and potential impact. GOST mandates classification of vulnerabilities by severity level with justification and risk calculation. Documentation includes precise description of conditions triggering the vulnerability and reproduction steps.

  • Testing input handling and validation mechanisms
  • Analysis of authentication and session management controls
  • Assessment of sensitive data protection in transit and storage

Vulnerability Demonstration and Controlled Exploitation

This phase involves controlled exploitation of identified vulnerabilities to confirm their real existence and assess actual impact. Exploitation is performed minimally and only to the extent necessary to prove the vulnerability exists. The tester documents each step precisely, including tools used, requests submitted, and results obtained.

When working with critical systems, minimize the risk of unintended denial of service or data corruption. GOST emphasizes the importance of reversibility in performed operations and immediate cessation of exploitation if unexpected consequences occur. Exploitation results must be reproducible and verifiable upon repeated testing.

  • Use minimal impact necessary to confirm vulnerability existence
  • Document exact sequence of actions and commands executed
  • Cease immediately if unforeseen consequences become apparent

Post-Exploitation Analysis and Privilege Assessment

After successful initial exploitation, analyze what capabilities have been gained and how they enable further penetration of the system. This phase determines what data becomes accessible, which additional accounts or privileges may be obtained, and the impact on other system components. The tester evaluates lateral movement possibilities, privilege escalation opportunities, and access to critical assets.

Results are analyzed through the lens of attack chaining: how combinations of multiple relatively simple vulnerabilities can lead to full system compromise. GOST requires documentation of the complete attack chain with description of each transition between access levels and the cumulative impact on system security.

  • Assessment of obtained access level and privileges
  • Analysis of lateral movement possibilities within the network
  • Documentation of complete attack chain from initial access to critical assets

Documentation and Reporting

Complete documentation of the testing process and findings is a mandatory GOST requirement. The report must contain an executive summary for management, technical description of each vulnerability, step-by-step reproduction instructions, and remediation recommendations. Each vulnerability is classified with severity level, potential impact, and remediation urgency.

Remediation recommendations must be specific and technically implementable, including code examples and configuration changes. The report is coordinated with the client and stored per information protection requirements. GOST requires preservation of testing evidence, including tool logs, screenshots, video recordings of critical exploitation moments, and client correspondence.

  • Executive summary highlighting key findings and business risks
  • Technical description of each vulnerability with payload examples and results
  • Specific remediation recommendations with code and configuration examples

Remediation Verification and Retesting

Upon completion of vulnerability remediation, retesting is performed to confirm the effectiveness of corrective measures. The tester verifies that previously discovered vulnerabilities are genuinely eliminated and no new vulnerabilities have been introduced. This phase includes verification that fixes did not cause security or functionality regression.

GOST specifies that retesting should occur within timeframes established in the agreement, typically no later than two weeks after remediation. Retesting results are documented in a separate report confirming successful vulnerability remediation. The organization receives confirmation of remediation effectiveness before deploying the updated application to production.

  • Verification of each previously discovered vulnerability
  • Check for new vulnerabilities introduced by remediation changes
  • Documentation of retesting results and confirmed remediation status

Sources

PENTEST.RED / RED JOURNAL