Review Cobalt pentest methodologies for external networks (includes instances of Microsoft Office 365).
:::info External network penetration testing is a process in which a tester uses simulated attacks to identify potential security vulnerabilities in an external network.
:::
We follow an industry-standard methodology primarily based on the Open Source Security Testing Methodology Manual (OSSTMM).
Penetration testing of an external network includes the following stages:
When testing Microsoft Office 365 instances, pentesters look into data security and encryption and verify access controls, in addition to testing the network that is hosting the services that are in scope.
:::info
The tools that our pentesters use during each phase may vary from test to test.
:::
The Cobalt security assessment team carries out testing without the following, unless it’s required as part of the pentest scope:
However, you’re welcome to add network diagrams and other details when describing your asset.
Cobalt pentesters search for all information that a malicious user might find. For example, to connect to the internet, you typically have shared some information:
During the initial phase of testing, pentesters determine what information is publicly available. They examine the following:
During this testing phase, pentesters use multiple tools, such as:
With these tools, pentesters can find:
With this information, our pentesters can identify potential weaknesses, such as:
After gathering all available information, our pentesters probe the resources belonging to the targeted organization. These tests involve several stages:
:::info
During this testing phase, pentesters use multiple tools, such as:
:::
As certain vulnerabilities and exploits could paralyze, damage, or alter the content of the network, our pentesters do not perform these attacks. They do make note of the possible risks. For example, our pentesters won’t run exploits that:
Pentesters perform a complete port scan on the IP address ranges for your asset. From this information, pentesters can identify public-facing machines and resources, along with their functionality.
For example, the following services require access to the outside world to function:
All of these services leave characteristic signatures that a port scan can detect.
Based on the results of the initial port scan, our pentesters work to identify:
In some cases, an externally exposed machine may have open services that don’t have functions associated with them. Pentesters can identify and target them for testing.
Cobalt pentesters follow up by identifying vulnerabilities in the external-facing portion of the network. Their goal is to penetrate external endpoints and gain access to the internal LAN and the organization’s resources.
If a potential attacker achieves this goal, an organization could face:
:::info
During this testing phase, pentesters use multiple tools, such as:
:::
During manual assessment, Cobalt pentesters examine specific resources that they identified. In most cases, pentesters focus on visibly open services:
While pentesters perform checks based on the specifics of a given situation, a common scenario involves examining the following:
:::info
During this testing phase, pentesters use multiple tools, such as:
:::
For organizations to use the internet, their network users need the ability to query DNS servers. Some organizations have their own DNS server, and some rely on external DNS servers. If an organization’s internal DNS server fails, this could cause their internet connection to go down.
Attackers may also obtain internal knowledge from a DNS server, such as:
Let’s look at an example of a serious DNS configuration error that may occur. When an organization allows unknown internet users to perform a DNS zone transfer, an attacker may get access to valuable information about the network.
All connections to the internet typically go through a border router managed by the Internet Service Provider (ISP). However, sometimes routers remain unpatched for an extended period, or default user accounts remain active.
We locate all visible routers, establish the manufacturer and operating system (OS), then check for potential vulnerabilities. Our tests include:
adminA firewall is designed to be the main gateway to an organization, with rules to protect internal resources. An attacker may get access to the firewall technology, so we don’t recommend treating it as an “out-of-the-box” solution. An organization should configure a firewall for the specific needs of their business, and keep it up to date through patching and maintenance.
Our pentesters look for configuration errors that could leave a path into the corporate LAN. Pentesters attempt to perform firewall attacks, such as:
Web servers are vulnerable to defacement attacks, or could be used as a launching pad for further attacks against internal networks.
Cobalt pentesters scan all web servers (client side) for potential exploits and vulnerabilities, such as:
Cobalt pentesters check SMTP, POP3, and IMAP on the mail gateway for open relay vulnerabilities. Your mail servers should:
Attackers could exploit an open relay to flood the mail server with spam, which could lead to the domain being denylisted.
Pentesters examine the mail server using a variety of methods, such as sending emails to non-existent domains.
Corporate network infrastructures may require connections to several other subsidiary offices around the globe over a VPN. While VPNs support secure communication, they may be vulnerable to the same configuration problems as firewalls, because firewalls handle the VPN.
An improperly configured VPN to a subsidiary site could be an attack vector to the main corporate network.
As researchers discover vulnerabilities and security flaws in software, software vendors release patches for their products. Our pentesters search for outdated and unpatched versions of software. They run tests against published and patched exploits.
Older versions have lower security thresholds and leave data vulnerable. According to the SANS Institute, some of the most common vulnerabilities are based on outdated versions of Office 365. Cobalt can perform pentests for Office 365 instances.
Cobalt pentesters can test legacy protocols such as POP3, IMAP, and SMTP for known vulnerabilities. They verify if the use of these protocols is secured against documented security flaws.
Cobalt pentesters use various custom and publicly available tools throughout a pentest, such as:
Cobalt pentesters report and triage all vulnerabilities during the assessment. You can review details of all findings, in real time, through the Cobalt platform. In these findings, as well as in any report, Cobalt’s pentesters include detailed information, including:
You can remediate findings during and after the pentest. Then you can submit findings for retest. Our pentesters test the updated components and retest vulnerabilities to ensure that there are no security-related residual risks.