Image
 
linkedin_logo.png rss_logo.jpg
twitter_logo.png youtube_logo.jpg
Latest Additions
 
EH-Net Login
Welcome Guest.






Lost Password?
No account yet? Register
Who's Online
We have 55 guests online
 
Free Business and Tech Magazines and eBooks

You are here: Home arrow Ethical Hacking Discussions and Related Certificationsarrow Network Pen Testingarrow Penetration Test Report
EH-Net
May 18, 2013, 10:44:58 PM *
Welcome, Guest. Please login or register.
Did you miss your activation email?

Login with username, password and session length
News: Go back to The Ethical Hacker Network Online Magazine Home Page
 
   Home   Help Calendar Login Register  
Pages: [1]   Go Down
  Print  
Author Topic: Penetration Test Report  (Read 10471 times)
0 Members and 1 Guest are viewing this topic.
fx0ne
Newbie
*
Offline Offline

Posts: 7


View Profile
« on: July 06, 2009, 05:31:09 PM »

Hi all,

I have been an ethical hacker for about 6 years but mainly operating out of Africa where PT is still being regarded as some sort of "black magic". Most of our clients are big financial institutions and a conglomerates.

I have been a passive member of this forum for some time now and would like to share with you a VA/PT report framework that i came up with from my experience consulting in this field. I do not know how reports are structured in other parts of the world, but i do know that other than the engagement itself, the report serves to justify the derived value around these parts.

I have googled for sample reports but to say i came up short is a masterpiece of understatement. What i found were either too verbose and grandiose or downright narrow in scope missing out salient but pertinent details in mostly  audacious attempts at describing all the technical input and results  - Detailed layout, logical flow and visual analysis are conspicuous only by their absence.

I have always believed that in order to get inside the mentality, first we have to jettison the PT myth. Furthermore I am also of the opinion that a VA/PT report should be as simple and clear as it is concise  and should cut across all strata of audience not just the technically minded.

All these put together led me to put up what is the first draft of the Open Source Security Assessment Report (OSSAR v 0.5). This is something that will be updated as often as i can with new information. I will kindly request members to download it and give an objective opinion on the material. I am very much interested in what this community thinks. Comments (+ve or -ve), suggestions and modifications are welcomed.

This is a VA/PT report for a fictitious bank called eClipse Bank PLC carried out by another fictitious company Cynergi Solutions Inc. All names, URLs, IPs, etc are fictitious. Some of the vulnerabilities discussed have actually occurred for real but i have replaced all the pesky details.

It can  be downloaded here http://uploading.com/files/E5MHOS2U/ossar_v0.5.pdf.html

Thanks
« Last Edit: July 06, 2009, 05:33:37 PM by fx0ne » Logged
BillV
Hero Member
*****
Offline Offline

Posts: 1892


View Profile WWW
« Reply #1 on: July 06, 2009, 06:29:51 PM »

I'm going to have to take a closer look and read through it, but right away I can say that I'm pretty sure you can't be using the 'LPT' logos/images in an "open source" report....
Logged
UNIX
Hero Member
*****
Offline Offline

Posts: 1234


View Profile
« Reply #2 on: July 07, 2009, 12:44:39 AM »

I will take a closer look too when I have some more time. However, I can already say that such a project is much appreciated and welcomed.

Some time ago I searched for some sample reports but did not find many free resources. One I found is from Offensive Security which can be found here.
Another one which is OSSTMM (Open Source Security Testing Methodology Manual) also includes the things a report should contain and is also widely used in Europe. It can be read here.
Third one I would like to mention is the Penetration Testing Framework which can be found here and inlcudes also some interesting things.
Sometimes it may be that the report itself is not included in the above mentioned and others, but it is said what is to be expected - with this information it should be possible to create your own report.

Although I like to pick the "best" things out of each and use it for my own reports, clients often like to stick to one, e.g. the OSSTMM.

I am really looking forward to read you approach. Thanks for sharing.
Logged
fx0ne
Newbie
*
Offline Offline

Posts: 7


View Profile
« Reply #3 on: July 07, 2009, 01:41:02 AM »

@BillV

Thanks for the observation. I will remove the LPT images in the upcoming version.

@awesec

Thanks expecting your feedback
Logged
fx0ne
Newbie
*
Offline Offline

Posts: 7


View Profile
« Reply #4 on: July 07, 2009, 02:14:38 AM »

An amended copy of ossar can be downloaded here.

http://www.digitalencode.net/ossar/ossar_v0.5.pdf

Thanks
Logged
ethicalhack3r
Full Member
***
Offline Offline

Posts: 139


View Profile WWW
« Reply #5 on: July 07, 2009, 02:50:11 AM »

Will have a look. Dont forget that the OWASP Testing Guide has some information on witting reports too.

EDIT---

Good example. Im not sure about using a real test for the report?! Or is that just for realism?

Quote
This document contains confidential and proprietary information.
It is intended for the exclusive use of eClipse Bank .
Unauthorized use or reproduction of this document is prohibited
« Last Edit: July 07, 2009, 02:56:13 AM by ethicalhack3r » Logged
UNIX
Hero Member
*****
Offline Offline

Posts: 1234


View Profile
« Reply #6 on: July 07, 2009, 03:27:52 AM »

Quote
This is a VA/PT report for a fictitious bank called eClipse Bank PLC carried out by another fictitious company Cynergi Solutions Inc. All names, URLs, IPs, etc are fictitious. Some of the vulnerabilities discussed have actually occurred for real but i have replaced all the pesky details.

Wink
Logged
ethicalhack3r
Full Member
***
Offline Offline

Posts: 139


View Profile WWW
« Reply #7 on: July 07, 2009, 03:53:59 AM »

Quote
This is a VA/PT report for a fictitious bank called eClipse Bank PLC carried out by another fictitious company Cynergi Solutions Inc. All names, URLs, IPs, etc are fictitious. Some of the vulnerabilities discussed have actually occurred for real but i have replaced all the pesky details.

Wink

 Undecided I should have read a little more. lol
Logged
dalepearson
Sr. Member
****
Offline Offline

Posts: 357


View Profile WWW
« Reply #8 on: July 07, 2009, 08:51:42 AM »

Thanks for taking the time to share your sample report. Like you say (and rightly so in some cases) there are not many sample reports available freely on the web, but most companies if you approach them will give you a sample.

I have has a look through and I did think the content was good, as people come to expect from these reports. Personally I did think that there was the occasionaly use of images without justification. I know a picture speaks a thousand words, but perhaps some additional commentry to accompany the imaging would help.
Finally perhaps I missed it, but the results dont give any detail as to if you exploited the vulnerabilities, or if the rating is just adapted from the Vuln scanners you have used. I know many organisations dont like what I call a true pen test and dont want things to be exploited, but on some occasions you may come across couter controls that may actually reduce the rating of a found issue.

I am probably being to picky as I see alot of these reports, but good work and thanks again for sharing, I am sure it will help out some of the readers.
Logged

don
Editor-In-Chief
Administrator
Hero Member
*****
Offline Offline

Posts: 4165


Editor-In-Chief


View Profile WWW
« Reply #9 on: July 07, 2009, 11:08:52 AM »

Welcome to EH-Net and thanks for the nice contribution to the comunity at-large.

Don
Logged

CISSP, MCSE, CSTA, Security+ SME
fx0ne
Newbie
*
Offline Offline

Posts: 7


View Profile
« Reply #10 on: July 07, 2009, 12:11:03 PM »

@ dalepearson

Thanks for the comments. Your observations are well noted. Some of the vulnerabilities were exploited especially as regards the web application and were given risk ratings accordingly and the false positives were duly tested and risk ratings lowered

@ don

Thanks.
Logged
fx0ne
Newbie
*
Offline Offline

Posts: 7


View Profile
« Reply #11 on: October 15, 2009, 12:16:34 PM »

I have been a bit busy lately but recently made some amendments to OSSAR (v1.0) based on the feedback received from forum members. I'm pretty sure I have omitted some suggestions because of my pressing schedule. Therefore, in addition to posting both the pdf copy, an editable version in Open Office odt format is also provided. The documents can be downloaded here:

https://sourceforge.net/projects/ossar/files/ossar_v1.0.pdf/download
https://sourceforge.net/projects/ossar/files/ossar_v1.0.odt/download

Cheers
« Last Edit: October 20, 2009, 09:48:35 AM by fx0ne » Logged
Pages: [1]   Go Up
  Print  
 
Jump to:  

Powered by MySQL Powered by PHP Powered by SMF 1.1.18 | SMF © 2013, Simple Machines
Joomla Bridge by JoomlaHacks.com
Valid XHTML 1.0! Valid CSS!
Page created in 0.075 seconds with 23 queries.
 
Exclusive Deal

sansfire13_245x90_cw90.jpg
SANSFIRE 2013
June 15 - 22

5% Off w/ Code: EHN_5

SANS Deals 4 EH-Netters
5% OFF Any SANS Course in Any Format!
Coupon Code: EHN_5 Including SANS Rocky Mountain 2013 & SANS Boston 2013
Polls
Compared to this year, 2013 will be:
 
Recent Forum Topics
EH-Net News Feeds
Latest Additions
 
         
Advertisement

© 2013 The Ethical Hacker Network
Joomla! is Free Software released under the GNU/GPL License.