Home
Calendar
Certifications
Columns
Features
Forum
Resources
Vitals
Latest Additions
April 2013 Free Giveaway Sponsor - eLearnSecurity
Human Intelligence to Navigate the Security Data Deluge
February 2013 Free Giveaway Winner of SANS CyberCon Training
Interview: Bugcrowd Founders on Herding Ninjas for Crowdsourced Bug Bounties
Network Forensics: The Tree in the Forest
March 2013 Free Giveaway Sponsor - Mile2
Book Review: Violent Python
February 2013 Free Giveaway Sponsor - SANS
Holiday 2012 Free Giveaway Winner of Metasploit Pro by Rapid7
Course Review: SANS FOR408 Computer Forensic Investigations – Windows In-Depth
The Security Consulting Sugar High
Tutorial: Fun with SMB on the Command Line
Interview: Ilia Kolochenko, CEO of High-Tech Bridge
October 2012 Free Giveaway Winner of LearningGate Training
The Broken: Assessing Corporate Security in 2012 to Make a Better 2013
EH-Net Login
Welcome Guest.
Username:
Password:
Remember me
Lost Password?
No account yet?
Register
Who's Online
We have 31 guests online
You are here:
Home
Ethical Hacking Discussions and Related Certifications
Network Pen Testing
Penetration Test Report
EH-Net
May 18, 2013, 09:40:37 PM
Welcome,
Guest
. Please
login
or
register
.
Did you miss your
activation email?
1 Hour
1 Day
1 Week
1 Month
Forever
Login with username, password and session length
News
: Go back to The Ethical Hacker Network Online Magazine
Home Page
Home
Help
Calendar
Login
Register
EH-Net
>
Ethical Hacking Discussions and Related Certifications
>
Network Pen Testing
(Moderator:
don
) >
Penetration Test Report
Pages: [
1
]
Go Down
« previous
next »
Print
Author
Topic: Penetration Test Report (Read 10470 times)
0 Members and 1 Guest are viewing this topic.
fx0ne
Newbie
Offline
Posts: 7
Penetration Test Report
«
on:
July 06, 2009, 05:31:09 PM »
Hi all,
I have been an ethical hacker for about 6 years but mainly operating out of Africa where PT is still being regarded as some sort of "black magic". Most of our clients are big financial institutions and a conglomerates.
I have been a passive member of this forum for some time now and would like to share with you a VA/PT report framework that i came up with from my experience consulting in this field. I do not know how reports are structured in other parts of the world, but i do know that other than the engagement itself, the report serves to justify the derived value around these parts.
I have googled for sample reports but to say i came up short is a masterpiece of understatement. What i found were either too verbose and grandiose or downright narrow in scope missing out salient but pertinent details in mostly audacious attempts at describing all the technical input and results - Detailed layout, logical flow and visual analysis are conspicuous only by their absence.
I have always believed that in order to get inside the mentality, first we have to jettison the PT myth. Furthermore I am also of the opinion that a VA/PT report should be as simple and clear as it is concise and should cut across all strata of audience not just the technically minded.
All these put together led me to put up what is the first draft of the Open Source Security Assessment Report (OSSAR v 0.5). This is something that will be updated as often as i can with new information. I will kindly request members to download it and give an objective opinion on the material. I am very much interested in what this community thinks. Comments (+ve or -ve), suggestions and modifications are welcomed.
This is a VA/PT report for a fictitious bank called eClipse Bank PLC carried out by another fictitious company Cynergi Solutions Inc. All names, URLs, IPs, etc are fictitious. Some of the vulnerabilities discussed have actually occurred for real but i have replaced all the pesky details.
It can be downloaded here
http://uploading.com/files/E5MHOS2U/ossar_v0.5.pdf.html
Thanks
«
Last Edit: July 06, 2009, 05:33:37 PM by fx0ne
»
Logged
BillV
Hero Member
Offline
Posts: 1892
Re: Penetration Test Report
«
Reply #1 on:
July 06, 2009, 06:29:51 PM »
I'm going to have to take a closer look and read through it, but right away I can say that I'm pretty sure you can't be using the 'LPT' logos/images in an "open source" report....
Logged
UNIX
Hero Member
Offline
Posts: 1234
Re: Penetration Test Report
«
Reply #2 on:
July 07, 2009, 12:44:39 AM »
I will take a closer look too when I have some more time. However, I can already say that such a project is much appreciated and welcomed.
Some time ago I searched for some sample reports but did not find many free resources. One I found is from Offensive Security which can be found
here
.
Another one which is OSSTMM (Open Source Security Testing Methodology Manual) also includes the things a report should contain and is also widely used in Europe. It can be read
here
.
Third one I would like to mention is the Penetration Testing Framework which can be found
here
and inlcudes also some interesting things.
Sometimes it may be that the report itself is not included in the above mentioned and others, but it is said what is to be expected - with this information it should be possible to create your own report.
Although I like to pick the "best" things out of each and use it for my own reports, clients often like to stick to one, e.g. the OSSTMM.
I am really looking forward to read you approach. Thanks for sharing.
Logged
fx0ne
Newbie
Offline
Posts: 7
Re: Penetration Test Report
«
Reply #3 on:
July 07, 2009, 01:41:02 AM »
@BillV
Thanks for the observation. I will remove the LPT images in the upcoming version.
@awesec
Thanks expecting your feedback
Logged
fx0ne
Newbie
Offline
Posts: 7
Re: Penetration Test Report
«
Reply #4 on:
July 07, 2009, 02:14:38 AM »
An amended copy of ossar can be downloaded here.
http://www.digitalencode.net/ossar/ossar_v0.5.pdf
Thanks
Logged
ethicalhack3r
Full Member
Offline
Posts: 139
Re: Penetration Test Report
«
Reply #5 on:
July 07, 2009, 02:50:11 AM »
Will have a look. Dont forget that the OWASP Testing Guide has some information on witting reports too.
EDIT---
Good example. Im not sure about using a real test for the report?! Or is that just for realism?
Quote
This document contains confidential and proprietary information.
It is intended for the exclusive use of eClipse Bank .
Unauthorized use or reproduction of this document is prohibited
«
Last Edit: July 07, 2009, 02:56:13 AM by ethicalhack3r
»
Logged
UNIX
Hero Member
Offline
Posts: 1234
Re: Penetration Test Report
«
Reply #6 on:
July 07, 2009, 03:27:52 AM »
Quote
This is a VA/PT report for a fictitious bank called eClipse Bank PLC carried out by another fictitious company Cynergi Solutions Inc. All names, URLs, IPs, etc are fictitious. Some of the vulnerabilities discussed have actually occurred for real but i have replaced all the pesky details.
Logged
ethicalhack3r
Full Member
Offline
Posts: 139
Re: Penetration Test Report
«
Reply #7 on:
July 07, 2009, 03:53:59 AM »
Quote from: awesec on July 07, 2009, 03:27:52 AM
Quote
This is a VA/PT report for a fictitious bank called eClipse Bank PLC carried out by another fictitious company Cynergi Solutions Inc. All names, URLs, IPs, etc are fictitious. Some of the vulnerabilities discussed have actually occurred for real but i have replaced all the pesky details.
I should have read a little more. lol
Logged
dalepearson
Sr. Member
Offline
Posts: 357
Re: Penetration Test Report
«
Reply #8 on:
July 07, 2009, 08:51:42 AM »
Thanks for taking the time to share your sample report. Like you say (and rightly so in some cases) there are not many sample reports available freely on the web, but most companies if you approach them will give you a sample.
I have has a look through and I did think the content was good, as people come to expect from these reports. Personally I did think that there was the occasionaly use of images without justification. I know a picture speaks a thousand words, but perhaps some additional commentry to accompany the imaging would help.
Finally perhaps I missed it, but the results dont give any detail as to if you exploited the vulnerabilities, or if the rating is just adapted from the Vuln scanners you have used. I know many organisations dont like what I call a true pen test and dont want things to be exploited, but on some occasions you may come across couter controls that may actually reduce the rating of a found issue.
I am probably being to picky as I see alot of these reports, but good work and thanks again for sharing, I am sure it will help out some of the readers.
Logged
:: Subliminal Hacking ::
/
:: Security Active Blog ::
don
Editor-In-Chief
Administrator
Hero Member
Offline
Posts: 4165
Editor-In-Chief
Re: Penetration Test Report
«
Reply #9 on:
July 07, 2009, 11:08:52 AM »
Welcome to EH-Net and thanks for the nice contribution to the comunity at-large.
Don
Logged
CISSP, MCSE, CSTA, Security+ SME
fx0ne
Newbie
Offline
Posts: 7
Re: Penetration Test Report
«
Reply #10 on:
July 07, 2009, 12:11:03 PM »
@ dalepearson
Thanks for the comments. Your observations are well noted. Some of the vulnerabilities were exploited especially as regards the web application and were given risk ratings accordingly and the false positives were duly tested and risk ratings lowered
@ don
Thanks.
Logged
fx0ne
Newbie
Offline
Posts: 7
Re: Penetration Test Report
«
Reply #11 on:
October 15, 2009, 12:16:34 PM »
I have been a bit busy lately but recently made some amendments to OSSAR (v1.0) based on the feedback received from forum members. I'm pretty sure I have omitted some suggestions because of my pressing schedule. Therefore, in addition to posting both the pdf copy, an editable version in Open Office odt format is also provided. The documents can be downloaded here:
https://sourceforge.net/projects/ossar/files/ossar_v1.0.pdf/download
https://sourceforge.net/projects/ossar/files/ossar_v1.0.odt/download
Cheers
«
Last Edit: October 20, 2009, 09:48:35 AM by fx0ne
»
Logged
Pages: [
1
]
Go Up
Print
« previous
next »
Jump to:
Please select a destination:
-----------------------------
EH-Net
-----------------------------
=> Calendar Of Events
===> ChicagoCon 2007
===> ChicagoCon 2008s
===> ChicagoCon 2008f
===> ChicagoCon 2009s
=> Ethical Hacktivism
=> News Items and General Discussion About EH-Net
===> Greetings
=> Special Events
-----------------------------
Ethical Hacking Discussions and Related Certifications
-----------------------------
=> General Certification
===> Networking
===> OS
===> Security
=> Compliance, Regulations & Standards
=> Control Systems
=> Cyber Warfare
=> Forensics
===> CCE / MCCE - (Master) Certified Computer Examiner
===> CHFI - Computer Hacking Forensic Investigator
===> EnCE - EnCase® Certified Examiner
===> GCFA - GIAC Certified Forensics Analyst
=> Hardware
=> Incident Response
===> CSIH - Computer Security Incident Handler
===> GCIH - GIAC Certified Incident Handler
=> Malware
===> Advisories
=> Mobile
=> Network Pen Testing
===> CEH - Certified Ethical Hacker
===> CPTC - Certified Penetration Testing Consultant
===> CPTE - Certified Penetration Testing Engineer
===> CSTA - Certified Security Testing Associate
===> eCPPT - eLearnSecurity Certified Professional Penetration Tester
===> ECSA - EC-Council Certified Security Analyst
===> GPEN - GIAC Certified Penetration Tester
===> OSCP - Offensive Security Certified Professional
=> Physical Security
=> Programming
=> Social Engineering
=> Web Applications
=> Wireless
===> CWNP Certs
===> GAWN - GIAC Assessing Wireless Networks
===> OSWP - Offensive Security Wireless Professional
=> Other
-----------------------------
Columns
-----------------------------
=> Editor-In-Chief
=> Andress
=> Gates
=> Haddix
=> Hadnagy
=> Heffner
=> Hoffman
=> Linn
=> RichM
=> Murray
=> J. Peltier
=> Weidman
=> Wilson
-----------------------------
Features
-----------------------------
=> /root
=> Book Reviews
=> Opinions
=> Skillz
===> Examples
===> May 06 - Star Hacks, Episode V: The Empire Hacks Back
===> July 06 - Hack Bill!
===> Sept 06 - Netcat in the Hat
===> Nov 06 - Hitch-Hackers Guide to the Galaxy
===> Dec 06 - A Christmas (Hacking) Story
===> Feb 07 - Charlottes Web Site
===> April 07 - Microsoft Office Space
===> June 07 - Serenity Hack
===> Oct 07 - Worst. Ethical. Hacker. Challenge. Ever.
===> Dec 07 - Frosty the Snow Crash
===> March 2008 - It Happened One Friday
===> Oct 2008 - Scooby Doo and the Crypto Caper
===> Dec 08 - Santa Claus Is Hacking to Town
===> Feb 2009 - Brady Bunch Boondoggle
===> July 2009 - Prison Break
===> October 2009 - SSHliders
===> December 2009 - Miracle on Thirty-Hack Street
===> December 2010 - The Nightmare Before Charlie Browns Christmas
-----------------------------
Resources
-----------------------------
=> Career Central
===> Looking For Work
===> Looking To Hire
=> Links to cool sites.
=> Mass Media
=> News from the Outside World
=> Tools
=> Tutorials
===> Tutorial Requests
Loading...
Exclusive Deal
SANSFIRE 2013
June 15 - 22
5% Off
w/ Code
:
EHN_5
SANS Deals 4 EH-Netters
5% OFF
Any
SANS Course
in Any Format!
Coupon Code:
EHN_5
Including
SANS Rocky Mountain 2013
&
SANS Boston 2013
Polls
Compared to this year, 2013 will be:
Great!
Better.
About the same.
Little worse.
FUBAR!
Recent Forum Topics
General Certification
: CPT Practical Submission
(0) by
z28power4u
OSCP - Offensive Security Certified Professional
: Class Scheduled 6/8 - Linux n00b
(5) by
MrTuxracer
Career Central
: Starter cert?
(0) by
Alert
Web Applications
: Nessus and Nikto
(4) by
Seen
Tutorials
: Need guidance
(7) by
impelse
Malware
: EICAR?
(2) by
SephStorm
Network Pen Testing
: Cracking salted MD5 hash
(4) by
n37sh@rk
CEH - Certified Ethical Hacker
: Passed my C|EH
(3) by
n37sh@rk
Mass Media
: EC-council hacked, irony at his best?
(0) by
j0rDy
Web Applications
: SQL Injection into an INSERT statement.
(6) by
eyenit0
Network Pen Testing
: Solution for sipXtapi INVITE Message CSeq Field Header Remote Overflow
(1) by
m0wgli
Web Applications
: dns
(2) by
H1t M0nk3y
Other
: BSides Boston
(0) by
3xban
Career Central
: InfoSec in Central, FL
(2) by
tturner
Web Applications
: Web vulnerability scanner
(4) by
H1t M0nk3y
EH-Net News Feeds
Latest Additions
Privacy Notice
for TDCC & All Properties
Free Business and Tech Magazines and eBooks
© 2013 The Ethical Hacker Network
Joomla!
is Free Software released under the GNU/GPL License.