• Home
  • Blog
  • About Us
  • Index
Menu

#_shellntel

Street Address
City, State, Zip
Phone Number
A SynerComm Team

Your Custom Text Here

#_shellntel

  • Home
  • Blog
  • About Us
  • Index

In Scope or Out of Scope?

December 23, 2020 Brian Judd

Just take me to the tool

In penetration testing, it’s important to have an accurate scope and even more important to stick to it. This can be simple when the scope is limited to a company’s internet service provider (ISP) or ARIN provided IP ranges. But in many cases, our client’s public systems have grown to include multiple cloud hosted servers, applications, and services. It may seem obvious to say that anything owned or managed by the company should be in-scope for testing, but how do we know what is “owned or managed”? Ideally, we’d test everything that creates risk to an organization, but that isn’t always possible… read on.

I led this article by stating that an accurate scope is critical to penetration testing. If the scope only includes the IP blocks provided by your ISP, you’re probably missing systems that should be tested. Alternately, pentesting a system that you don’t have permission to test could land you in hot water. The good news is that hosting providers like Amazon Web Services (AWS) and Azure allow penetration testing of systems within your account. In other words, because you manage them, you have the right to pentest them. In these environments, pentesting your individual servers (or services) does not affect “neighboring” systems or the cloud host’s infrastructure.

In addition to the many compute and storage providers, you may also have websites and applications that are hosted and managed by a 3rd party. These still create risk to your company, but the hosting provider has complete control over who has permission to perform testing. When there is custom code or sensitive data at play, you should be seeking (written) permission to pentest/assess these systems and applications. If the host is unable or unwilling to allow testing, they should provide evidence of their own independent testing.

There are also going to be cloud systems that, despite creating risk to your organization, can’t be tested at all. This includes software as a service (SaaS) applications like SalesForce, SAP,  and DocuSign. 

And you guessed it… there are also systems like Azure AD, Microsoft 365, and CloudFlare that are not explicitly in-scope, but their controls may not be avoidable during external pentests. MS 365 uses Azure AD which is basically a public extension of your on-premise (internal) Active Directory; complete with extremely high-performance authentication services. Most authentication attacks today take place directly against Azure AD due to its performance and public accessibility. In other words, an attacker could have your passwords before they ever touch a system on your network. Likewise, if your company uses CloudFlare to protect your websites and web applications, it inherently becomes part of the scope because testing of these apps should force you through their proxy/control.

Hopefully this information will help you plan for your next pentest or assessment. If your company maintains an accurate inventory of external systems that includes all of your data center and cloud systems, you’re already off to a great start. Still, there is always value in doing regular searches and discoveries for systems you may be missing. One method involves reviewing your external DNS to obtain a list of A and CNAME records for your domains.  (For ALL of your domains…)  By resolving all of your domains and subdomains you can easily come up with a pretty large list of IP addresses that are in some way tied to your company. Now all you need to do is lookup each IP to see what it’s hosting and who owns it. Easy right?

If you don’t already have a tool for looking up bulk lists of IP addresses or you prefer not to paste a list of your company’s IP addresses into someone else’s website, we’ve got a solution. Whodat.py was written to take very large lists of IP addresses and perform a series of whois and geoip lookups. If the IP address is owned by Amazon or Microsoft, additional details on the service or data center get added based the host’s online documentation. This tool was designed for regular use by our penetration testers, but its concepts and capabilities are a core functionality of our CASM Engine™ and our suite of Continuous Attack Surface Management and Continuous Penetration Testing subscriptions.

@njoyzrd

Link to tool: https://github.com/Shellntel/whodat

Tags CASM, Tools
Comment
Older Posts →
Latest Blog Posts
Modern Attack Surface.png
December 23, 2020
In Scope or Out of Scope?
December 23, 2020
Read more →
December 23, 2020
Building a Pwnagotchi
May 15, 2020
Building a Pwnagotchi
May 15, 2020
Read more →
May 15, 2020
AWS Metadata Endpoint - How to not get pwned like Capital One
August 27, 2019
AWS Metadata Endpoint - How to not get pwned like Capital One
August 27, 2019
Read more →
August 27, 2019
How to build a (2nd) 8 GPU password cracker
February 20, 2019
How to build a (2nd) 8 GPU password cracker
February 20, 2019
Read more →
February 20, 2019
DA 101 - Protecting your Domain Admin Account
October 22, 2018
DA 101 - Protecting your Domain Admin Account
October 22, 2018
Read more →
October 22, 2018
OpenSSH < 7.7 - Username Enumeration Exploit
August 21, 2018
OpenSSH < 7.7 - Username Enumeration Exploit
August 21, 2018

On August 15th, 2018 a vulnerability was posted on the OSS-Security list. This post explained that OpenSSH (all versions prior to and including 7.7) is vulnerable to username enumeration by sending a malformed public key authentication request (SSH2_MSG_USERAUTH_REQUEST with type publickey) to the service.

Read more →
August 21, 2018
March 17, 2017
Thoughts on Blocking Powershell.exe
March 17, 2017
Read more →
March 17, 2017
How to build a 8 GPU password cracker
February 13, 2017
How to build a 8 GPU password cracker
February 13, 2017
Read more →
February 13, 2017
The Upside Down - Ventures into the 5GHZ Spectrum
October 26, 2016
The Upside Down - Ventures into the 5GHZ Spectrum
October 26, 2016
Read more →
October 26, 2016
October 6, 2016
spin-up: Quickly Launch a Provisioned EC2 Attack Server
October 6, 2016
Read more →
October 6, 2016
September 23, 2016
Luckystrike: An Evil Office Document Generator.
September 23, 2016
Read more →
September 23, 2016
The Number One Pentesting Tool You're Not Using
August 3, 2016
The Number One Pentesting Tool You're Not Using
August 3, 2016
Read more →
August 3, 2016
Screen Shot 2016-07-08 at 10.22.17 AM.png
July 8, 2016
Invoke-SMBAutoBrute.ps1 - Smart SMB Brute Forcing
July 8, 2016
Read more →
July 8, 2016
Screen Shot 2016-06-07 at 4.13.13 PM.png
June 8, 2016
Weaponizing Nessus
June 8, 2016
Read more →
June 8, 2016
May 24, 2016
Update to ProxyCannon
May 24, 2016
Read more →
May 24, 2016
May 12, 2016
VPN over DNS
May 12, 2016
Read more →
May 12, 2016
February 22, 2016
Websocket based egress buster
February 22, 2016
Read more →
February 22, 2016
February 18, 2016
Abusing Exchange Web Service - Part 1
February 18, 2016
Read more →
February 18, 2016
Screen Shot 2016-02-04 at 2.36.33 PM.png
February 8, 2016
Why Security Awareness Training Fails
February 8, 2016
Read more →
February 8, 2016
October 6, 2015
Assisted directory brute forcing
October 6, 2015
Read more →
October 6, 2015
crEAP - Harvesting Users on Enterprise Wireless Networks
October 1, 2015
crEAP - Harvesting Users on Enterprise Wireless Networks
October 1, 2015
Read more →
October 1, 2015
September 26, 2015
[UPDATE] Creating your own private botnet for scanning.
September 26, 2015
Read more →
September 26, 2015
September 25, 2015
Drone Code Execution (Part 1)
September 25, 2015
Read more →
September 25, 2015
PowerShell Memory Scraping for Credit Cards
September 18, 2015
PowerShell Memory Scraping for Credit Cards
September 18, 2015
Read more →
September 18, 2015
September 9, 2015
Intro To Active Directory Delegation
September 9, 2015
Read more →
September 9, 2015
July 27, 2015
Using PowerShell & Unicorn to Get Persistence
July 27, 2015
Read more →
July 27, 2015
screenshot.png
July 14, 2015
Creating your own private botnet for scanning.
July 14, 2015
Read more →
July 14, 2015
June 18, 2015
Circle City Con: 2015 CTF Writeup
June 18, 2015
Read more →
June 18, 2015
Qualys Scanner API In Powershell Including External Ticket Creation
June 12, 2015
Qualys Scanner API In Powershell Including External Ticket Creation
June 12, 2015
Read more →
June 12, 2015
June 12, 2015
Validating the Effectiveness of Your Controls
June 12, 2015
Read more →
June 12, 2015

Shellntel™ - Brought to you by SynerComm