In a complete penetration testing workflow, nearly half of the time is actually spent on how to write reports. The work of a penetration testing engineer not only requires a high level of penetration testing, but also requires an easy-to-understand explanation of a profound techn

A complete penetration test workflow actually spends nearly half of the time on how to write reports. The work of penetration testing engineers not only requires a superb penetration testing level, but also requires a simple and easy-to-understand explanation of a profound technical point, which can be understood even by people who do not understand safety at all.

So, what exactly does a standard penetration test report look like? In this issue, follow Sister Zhiliao to learn the relevant knowledge of penetration test reports~

01

The importance of penetration test reports

Penetration test is a scientific process, like all scientific processes, it should be independent and repeatable. When the customer is not satisfied with the test results, he has the right to ask another tester to reproduce it. If your report does not specify the conclusion in detail, the second tester will not know where to start, and the conclusions drawn are very likely to be different, and even miss related vulnerabilities.

As an example:

fuzzy description: "I detected an open TCP port using the port scanner. "

Clear and clear description: "I use Nmap 5.50, SYN scan of a section of ports, and an open TCP port was found. The

command is: nmap –sS –p 7000-8000”

report is the output of the real test process and is evidence of the real test results. For customers, they may not have much interest in the content of the report, but this report is their only evidence to prove the test cost.

02

How to prepare penetration test records?

Step 1

Prepare penetration test record

Test record is the log of the execution process. After the daily test work is completed, the results of the day should be recorded. Although the content does not need to be too detailed, the focus of the test must be recorded:

·Project to be tested

·To be used tools or methods

·Detection process description

·Detection process description

·Project to be tested

·Project or method used

·Detection process description

·Projects to be tested

·Projects to be tested

·To be used

·To be used

·To be described

·To be tested ·Detection result description

·The key screenshot of the process (show with results)

Step 2

Writing a penetration test report

Report is a summary of the entire test test operation results. The following outline will be written:

Foreword: Description of the purpose of the execution of the test

Declaration: Address the negotiation matters according to the penetration test consent form, which are listed here, and are usually used as Party B's disclaimer.

Abstract: summarizes the weaknesses and vulnerabilities found in this penetration test. If the system has a good protection mechanism, it can also be written here and provided to Party A for other website systems as management reference.

execution method: "abstract" explains the methodology of the test, the method of the test, the execution time and the evaluation method of the test. The evaluation method is subject to the conditions agreed by both parties, such as: discovering medium and high-risk projects, being able to raise power successfully, being able to complete the insertion of flags (that is, uploading the specified file or modifying the web page content in the target website), interrupting the system service...

Execution process description: According to the project agreed by both parties, the test "result" should be explained. Whether it can be successfully penetrated or not, the execution procedure should be explained.

marked "Detailed execution steps, such as "Permeation Test Record Table"" so that the penetration test record table can be introduced into the report and list the explanation of the risk of this operation. For example, after the test is completed, Party B personnel evaluated their risk level for all test targets, and used the degree of impact caused by the test target and the possibility of occurrence as a factor to obtain the risk level. The evaluation is as follows:

Note on matters and suggestions to improve: This is the most important part of the entire report. Any penetration test must provide customer protection or weakness correction suggestions. In fact, as long as the type of weakness can be defined, because the protection suggestions can be found through search, it is best to explain the suggestions in detail in this section to improve customer satisfaction.

attachment or reference file (if none, you can omit it): Some companies will list the qualifications of group members here for Party A's reference.

Step 3

What are the precautions for writing a report?

Test record is the log of the execution process. After the daily test work is completed, the results of the day should be recorded. Although the content does not need to be too detailed, the focus of the test must be recorded:

A good report can add points to the test operation, and a bad report will ruin the efforts of the testers, so writing a penetration test report should not be too casual. The following are three writing tips for reference:

① Key vulnerabilities should be written in straightforward words so that the supervisor can see it at a glance. When you open the report, you can feel the penetration test. Value

②When writing suggestions for fixing vulnerabilities, it is best to say something, and attach a patch example

③The chart is more important than text, and the key positions are attached with figures to prove the data, data comparison or summary, to avoid not being able to catch the key

④Test results, weaknesses, vulnerabilities must be raised, and correction suggestions are given