Security+ Academy · पाठ

पैठ परीक्षण के चरण: टोही से रिपोर्ट तक

पैठ परीक्षण के जीवनचक्र का अनुसरण कीजिए: टोही, स्कैनिंग, शोषण, शोषण-पश्चात गतिविधियाँ और सुधार कार्य को दिशा देने वाली अंतिम रिपोर्ट।

पाठ 3, कुल 4 में से13 चरण

पैठ परीक्षण के चरण: टोही से रिपोर्ट तक, CoddyKit पर Security+ Academy का एक निःशुल्क पाठ है। यह 4 में से 3वाँ पाठ है। इस अध्ययन पथ के 3 तक कोई भी पाठ पूरा पढ़ना निःशुल्क है — इसके बाद CoddyKit PRO हर पाठ अनलॉक करता है, साथ ही अंतर्निर्मित कोड संपादक और चौबीसों घंटे एआई शिक्षक के साथ व्यावहारिक अभ्यास भी उपलब्ध कराता है। यह Security+ Academy सीखने के मार्ग का हिस्सा है और आपकी प्रगति वेब तथा CoddyKit ऐप पर सिंक होती रहती है। Security+ Academy पाठ्यक्रम में कुल 4 पाठ शामिल हैं।

Penetration Testing Lifecycle

एक structured penetration test निर्धारित lifecycle का पालन करता है, जो thorough coverage सुनिश्चित करता है, production systems के लिए risk को कम करता है और actionable results प्रदान करता है। सबसे व्यापक रूप से अपनाया गया framework PTES (Penetration Testing Execution Standard) से आता है और NIST approach के अनुरूप है। इसके phases हैं: Planning/Scoping, Reconnaissance, Scanning, Exploitation, Post-Exploitation और Reporting। प्रत्येक phase पिछले phase पर आधारित होता है — जिसे आपने discover नहीं किया है, उसका exploit नहीं कर सकते और जिसे document नहीं किया है, उसकी report नहीं कर सकते। Phases को छोड़ना या जल्दबाज़ी में पूरा करना incomplete assessments और unreliable findings का कारण बनता है।

# Penetration testing phases:
# 1. Planning & Scoping    (Rules of Engagement)
# 2. Reconnaissance        (OSINT + passive recon)
# 3. Scanning/Enumeration  (active discovery)
# 4. Exploitation          (attacking vulnerabilities)
# 5. Post-Exploitation     (lateral movement, persistence)
# 6. Reporting             (findings + recommendations)

Phase 1: Planning और Scoping

Planning phase engagement की legal और operational foundation स्थापित करता है। इसके प्रमुख deliverables में शामिल हैं: objectives और pricing परिभाषित करने वाला signed Statement of Work (SOW); authorized Targets, time windows, prohibited techniques, emergency contacts और data handling requirements निर्दिष्ट करने वाला Rules of Engagement (RoE) document; और success criteria की स्पष्ट definition (objective प्राप्त होने का अर्थ क्या है)। Scope को सटीक रूप से परिभाषित करना आवश्यक है, ताकि scope creep (अनजाने में unauthorized systems का testing) रोका जा सके और assessment में सबसे critical assets शामिल हों। किसी भी technical work के शुरू होने से पहले सभी communication channels और escalation procedures स्थापित किए जाते हैं।

# Scoping questions to answer:
# - Which IP ranges/domains are in scope?
# - Are cloud environments (AWS/Azure/GCP) in scope?
# - Are physical attacks in scope?
# - Are employees fair game for phishing?
# - Are denial-of-service techniques permitted?
# - What notification procedures exist?
# - Who is the authorized point of contact?
# - What is the test window (dates/times)?
# - How will data be protected and destroyed after?

Phase 2: Passive Reconnaissance (OSINT)

Passive reconnaissance Target के systems से सीधे interact किए बिना उसके बारे में information collect करता है — ऐसे public sources का उपयोग करके जो Target पर logs generate नहीं करते। Sources में शामिल हैं: WHOIS records (domain registration, registrant contact), DNS records, certificate transparency logs (जो subdomains उजागर करते हैं), LinkedIn (employee names, job titles, उपयोग की जा रही technologies), job postings (tech stack और tools उजागर करते हैं), Shodan/Censys (internet-facing services और open ports), GitHub repositories (source code, गलती से commit किए गए credentials) और Google dorking (sensitive files और exposed interfaces के लिए site-specific searches)।

# OSINT techniques (no target contact):
# WHOIS:
whois targetcompany.com

# DNS enumeration via public resolvers:
dig @8.8.8.8 targetcompany.com ANY
dnsx -d targetcompany.com -a -aaaa -cname -mx -ns

# Certificate transparency (subdomains):
curl 'https://crt.sh/?q=%.targetcompany.com&output=json'

# Google dorks:
# site:targetcompany.com filetype:pdf confidential
# site:targetcompany.com inurl:admin
# site:github.com targetcompany password OR apikey

Phase 2: Active Reconnaissance

Active reconnaissance में information gather करने के लिए Target systems से सीधे interact करना शामिल है। इससे Target पर logs generate होते हैं और यह passive recon की तुलना में स्वाभाविक रूप से अधिक noisy होता है। Techniques में Port scanning (Nmap), service Enumeration, DNS zone transfer attempts और banner grabbing शामिल हैं। Reconnaissance और Scanning के बीच की सीमा स्पष्ट नहीं है — Reconnaissance का उद्देश्य information gathering है, जबकि Scanning का सामान्य अर्थ vulnerability identification होता है। फिर भी, active recon IDS/IPS alerts trigger कर सकता है और security-aware Target द्वारा detect किया जा सकता है। इसलिए testers engagement objective (detection test करना या stealth compromise करना) के आधार पर thoroughness और stealth में संतुलन बनाते हैं।

# Active reconnaissance techniques:
# Host discovery:
nmap -sn 192.168.1.0/24 -oG alive_hosts.txt

# DNS zone transfer (if misconfigured):
dig axfr @ns1.targetcompany.com targetcompany.com

# Banner grabbing:
nc -v 192.168.1.10 22    # SSH version
curl -I https://targetcompany.com  # web server header

# SMTP enumeration:
nmap --script smtp-enum-users 192.168.1.25

# Web crawler:
whatweb targetcompany.com

Phase 3: Scanning और Vulnerability Analysis

Scanning phase in-scope Targets पर open ports, services, software versions और known vulnerabilities को व्यवस्थित रूप से discover करता है। इस phase में service Enumeration के लिए Nmap और vulnerability scanning के लिए Nessus/OpenVAS जैसे tools का उपयोग किया जाता है। Pen tester scanner output की manual review करता है और findings को correlate करता है: Nmap द्वारा पहचाना गया Apache का कोई version CVE database में मौजूद known exploits से match कर सकता है। इस phase में Web applications की manual probing (Burp Suite के साथ) और authentication mechanisms का testing भी शामिल है। इसका output exploitation phase में आगे बढ़ाए जाने वाले संभावित attack paths की prioritized list होता है।

# Scanning phase workflow:
# 1. Port and service scan:
nmap -sV -sC -O 192.168.1.0/24 -oX services.xml

# 2. Vulnerability scan (Nessus/OpenVAS):
# Import Nmap results -> credentialed scan -> export report

# 3. Web application scanning:
burpsuite                              # manual + scanner
niklto -h https://192.168.1.10
wpscan --url https://targetsite.com   # WordPress-specific

# 4. Correlate version with CVEs:
# searchsploit apache 2.4.41
# Check NVD: https://nvd.nist.gov/vuln/search

Phase 4: Exploitation

Exploitation phase identified vulnerabilities का लाभ उठाकर unauthorized access, privilege escalation या अन्य defined objectives प्राप्त करने का प्रयास करता है। Exploitation को strictly scope और Rules of Engagement के भीतर रहना चाहिए। Techniques में unpatched vulnerabilities का exploitation (Metasploit या manual exploits का उपयोग करके), credential attacks (password spraying, default credentials, brute-forcing), Web application attacks (SQL injection, XSS exploitation) और authorized होने पर social engineering शामिल हैं। प्रत्येक action को timestamps के साथ document करना आवश्यक है: क्या किया गया, कब किया गया, उसका result क्या था और किस tool का उपयोग किया गया। यह documentation final report के evidence base का निर्माण करता है।

# Documentation during exploitation:
# Use a testing journal (OneNote, CherryTree, Obsidian)
# For each finding, record:
# - Date/time: 2026-06-15 14:32 UTC
# - Target: 192.168.1.25 (web-prod-01)
# - Finding: SQL injection in /login.php username parameter
# - Command: sqlmap -u 'http://target/login.php' --data 'user=*&pass=x'
# - Screenshot: login_sqli_01.png
# - Impact: retrieved admin credentials from users table
# - CVSS: 9.8 (Critical)

Phase 5: Post-Exploitation

Post-exploitation initial access प्राप्त होने के बाद शुरू होता है और यह जाँचता है कि Attacker अपनी पहुँच कितनी दूर तक बढ़ा सकता है। Activities में शामिल हैं: privilege escalation (limited user access से admin/root access प्राप्त करना), credential harvesting (hashes, tickets या plaintext passwords निकालना), lateral movement (harvest किए गए credentials का उपयोग करके अन्य systems तक पहुँचना), data discovery (compromised position से accessible sensitive data की पहचान करना) और persistence स्थापित करना (APT की long-term access का simulation करने के लिए)। उद्देश्य initial compromise के realistic impact को दिखाना है — केवल यह नहीं कि एक system pwned हुआ, बल्कि यह कि Attacker अंततः कहाँ तक पहुँच सकता था।

# Post-exploitation with Meterpreter (Metasploit):
meterpreter> sysinfo                  # OS/hostname
meterpreter> getuid                   # current user
meterpreter> getsystem                # attempt privilege escalation
meterpreter> hashdump                 # dump local NTLM hashes
meterpreter> run post/multi/gather/credentials
meterpreter> run post/windows/manage/migrate  # migrate to stable process

# Lateral movement (CrackMapExec with dumped hash):
crackmapexec smb 192.168.1.0/24 -u admin -H <NTLM_hash> --shares

Pivoting और Internal Network Access

Pivoting एक compromised Host को relay के रूप में उपयोग करके उन network segments तक पहुँचता है जो अन्यथा pen tester के लिए inaccessible होते हैं (जैसे, internal database VLAN, जो केवल application server से reachable हो)। Metasploit का route add command और SSH tunneling (ssh -L local forwarding के लिए या ssh -D SOCKS proxy के लिए) सामान्य pivot mechanisms हैं। Pivoting यह प्रदर्शित करता है कि network segmentation वास्तव में effective है या नहीं — एक अच्छी तरह segmented network को compromised DMZ server को internal databases तक पहुँचने से रोकना चाहिए, जबकि flat network free lateral movement की अनुमति देता है। Report में documented pivot paths यह स्पष्ट दिखाते हैं कि segmentation gaps कहाँ मौजूद हैं।

# SSH local port forward (pivot):
# Access MySQL on internal server through compromised host:
ssh -L 3306:10.30.30.5:3306 user@compromised_host
# Now connect to MySQL locally:
mysql -h 127.0.0.1 -P 3306 -u root

# SOCKS proxy for full network pivot:
ssh -D 1080 user@compromised_host
# Use proxychains to route tools through SOCKS proxy:
proxychains nmap -sT 10.30.30.0/24

# Metasploit route add:
route add 10.30.30.0/24 <session_id>

Cleanup और Evidence Preservation

Testing पूरा होने के बाद pen testers को clean up करना आवश्यक है — उनके द्वारा install किए गए backdoors, accounts और tools को remove करना। Real attackers के विपरीत, pen testers Rules of Engagement के तहत systems को उनकी pre-test state में restore करने के लिए बाध्य होते हैं। Cleanup items में शामिल हैं: बनाए गए user accounts को remove करना, छोड़ी गई files (payloads, tools) को delete करना, persistence mechanisms (WMI subscriptions, scheduled tasks, registry run keys) को remove करना और client से confirm करना कि सभी test artifacts हटाए जा चुके हैं। Evidence preservation समानांतर रूप से चलता है: report writing और संभावित legal reference के लिए सभी screenshots, tool output, logs और notes को secure format में सुरक्षित रखें।

# Post-test cleanup checklist:
# Windows:
# - Delete created accounts: net user testuser /delete
# - Remove scheduled tasks: schtasks /delete /tn 'TestTask'
# - Remove registry persistence: reg delete HKLM\...
# - Delete dropped files: del C:\Windows\Temp\payload.exe
# - Clear event logs (if authorized): wevtutil cl Security

# Linux:
# - Remove cron jobs: crontab -r
# - Remove added SSH keys: edit ~/.ssh/authorized_keys
# - Delete dropped files: rm /tmp/payload.sh

Phase 6: Reporting

Report वह ultimate deliverable है जो engagement को justify करता है और remediation को आगे बढ़ाता है। एक well-structured report में शामिल होते हैं: executive summary (risk rating, business impact, leadership के लिए top 3 findings); technical findings section (प्रत्येक finding के साथ severity, description, evidence, reproduction steps, business impact और specific remediation guidance); और raw tool output तथा detailed timelines वाला appendix। Reports को confidential वर्गीकृत किया जाता है — इनमें attack को दोहराने के लिए पर्याप्त detail होती है। Delivery में सामान्यतः एक debrief meeting शामिल होती है, जिसमें pen test team findings समझाती है और client के questions के answers देती है। अच्छी Reporting ही professional engagements को amateur scan dumps से अलग करती है।

Exam के लिए Passive बनाम Active Reconnaissance

Security+ में passive और active reconnaissance के बीच का अंतर अक्सर पूछा जाता है। Passive recon में Target systems से सीधे contact किए बिना public sources से information gather करना शामिल है — Target पर कोई logs create नहीं होते। Examples: WHOIS records पढ़ना, LinkedIn की review करना, certificate transparency logs को query करना और Shodan searches चलाना। Active recon में Target systems से सीधे interact करना शामिल है — Port scanning, banner grabbing और DNS zone transfer attempts। Active recon logs generate करता है और IDS alerts trigger कर सकता है। Real engagement में, Target network से कोई detectable contact करने से पहले map तैयार करने के लिए passive recon, active recon से पहले किया जाता है।

त्वरित जाँच

इस lesson से CompTIA Security+ (SY0-701) concepts की अपनी समझ जाँचें।

Lesson Recap

इस lesson में आपने सीखा: penetration testing planning, reconnaissance, scanning, exploitation, post-exploitation और reporting के structured lifecycle का पालन करता है; passive reconnaissance Target-side logs create किए बिना public OSINT sources का उपयोग करता है, जबकि active recon सीधे systems से interact करता है; और executive summary, technical findings तथा specific remediation guidance वाली final report security improvements को आगे बढ़ाने वाला मुख्य deliverable है। आगे हम CVSS scoring और vulnerability remediation को prioritize करने के तरीके का अध्ययन करेंगे।

शुरुआत निःशुल्क

एआई शिक्षक के साथ Security+ Academy सीखें — निःशुल्क

अपने ब्राउज़र में वास्तविक कोड लिखें और चलाएँ, चौबीसों घंटे एआई शिक्षक से तुरंत सहायता पाएँ, और वेब या ऐप पर वहीं से शुरू करें जहाँ आपने छोड़ा था।

पाठ्यक्रम
30
पाठ
120

अक्सर पूछे जाने वाले प्रश्न

क्या “पैठ परीक्षण के चरण: टोही से रिपोर्ट तक” पाठ निःशुल्क है?

हाँ — Security+ Academy अध्ययन पथ के 3 तक कोई भी पाठ, जिसमें “पैठ परीक्षण के चरण: टोही से रिपोर्ट तक” भी शामिल है, यहाँ वेब पर पूरा पढ़ना निःशुल्क है। इसके बाद CoddyKit PRO हर पाठ अनलॉक करता है, साथ ही अंतर्निर्मित कोड संपादक और चौबीसों घंटे एआई शिक्षक के साथ इंटरैक्टिव अभ्यास भी उपलब्ध कराता है। Security+ Academy पाठ्यक्रम में कुल 4 पाठ शामिल हैं।

“पैठ परीक्षण के चरण: टोही से रिपोर्ट तक” में मैं क्या सीखूँगा?

पैठ परीक्षण के जीवनचक्र का अनुसरण कीजिए: टोही, स्कैनिंग, शोषण, शोषण-पश्चात गतिविधियाँ और सुधार कार्य को दिशा देने वाली अंतिम रिपोर्ट। आप ब्राउज़र में सीधे चलाए जाने वाले व्यावहारिक कोड के साथ Security+ Academy का अभ्यास करते हैं, और पाठ पूरा करते समय 24/7 एआई ट्यूटर आपके प्रश्नों के उत्तर देता है।

क्या Security+ Academy शुरू करने के लिए मुझे किसी अनुभव की आवश्यकता है?

पहले के अनुभव की आवश्यकता नहीं है। CoddyKit पर Security+ Academy शुरुआती से लेकर उन्नत शिक्षार्थियों तक सभी के लिए व्यवस्थित किया गया है, इसलिए आप यहीं से या शुरुआत से सीखना शुरू कर सकते हैं और अपनी गति से आगे बढ़ सकते हैं। यह 4 में से 3वाँ पाठ है।

“पैठ परीक्षण के चरण: टोही से रिपोर्ट तक” पाठ पूरा करने में कितना समय लगता है?

CoddyKit का अधिकांश पाठ लगभग 5–10 मिनट में पूरा हो जाता है। हर पाठ छोटा और संवादात्मक है, इसलिए आप लगातार प्रगति करते हैं और वेब या ऐप पर वहीं से सीखना जारी रख सकते हैं जहाँ आपने छोड़ा था।

क्या मैं इस Security+ Academy पाठ में कोड लिख और चला सकता हूँ?

हाँ। हर Security+ Academy पाठ में एक अंतर्निर्मित कोड संपादक शामिल है, जिससे आप सीधे अपने ब्राउज़र में वास्तविक कोड लिख और चला सकते हैं और तुरंत एआई प्रतिक्रिया पा सकते हैं—स्थानीय सेटअप की आवश्यकता नहीं है।

इस पाठ्यक्रम के सभी पाठ

  1. कमज़ोरी स्कैनिंग बनाम पैठ परीक्षण
  2. सामान्य स्कैनिंग उपकरण: Nessus, OpenVAS, Nmap
  3. पैठ परीक्षण के चरण: टोही से रिपोर्ट तक
  4. CVSS स्कोरिंग और कमज़ोरी प्राथमिकता निर्धारण
← Security+ Academy पर वापस जाएँ