5 Phases Every Ethical Hacker Must Follow

5 Phases Every Ethical Hacker Must Follow

5 Phases Every Ethical Hacker Must Follow

Phases of Hacking

Introduction

The 5 Phases of hacking are designed to make Penetration testing easier. Contrary to what is seen in the movies and tv shows, Ethical Hacking is extremely methodical and thought-out. Ethical Hacking involves many steps successfully test a system, or entire networks, defenses.

It is not simply a case of inputting some random lines of code into a terminal, hoping to get lucky and infiltrate a targets system. It could take weeks of basic reconnaissance and social engineering to gain the minimum amount of information needed.

Because of the fact Ethically Hacking a system as a penetration tester is a difficult goal to achieve, all hackers follow a simple outline of the hacking process. These steps methodically break down the entire process into an easy-to-follow guideline that helps simplify ‘hacking’.

Caveats

This list pertains to simplifying the penetration testing process. Intended for informational and education purposes only. There will be no guide here on how to achieve the goal of each phase, but there will be helpful information regarding the tooling used by cybersecurity professionals to progress through the phases.

Hacking can be extremely destructive. Hacking Ethically requires consent. For instance, in a penetration testing environment, lab or sandbox. This is an informational and educational guide.

The 5 Phases Every Ethical Hacker Must Follow


1. Reconnaissance

The first phase every ethical hacker begins with, is reconnaissance of the target. This can take several weeks and is purely designed to gather as much information as possible regarding the target. By conducting recon, you can find out extremely pertinent information and use this advantage in the later phases.

Reconnaissance can take on many forms and is achieved through Open-Source Intelligence (OSINT). Read more about OSINT here.

As well as OSINT, reconnaissance can be done through tools built into Kali Linux like NMAP, recon-ng and Hping3. Sign up for e-mail notifications and follow our social media to be updated when we post tutorials on these tools.

2. Scanning

The next phase an Ethical Hacker must do to gain access to a system is Scanning. Scanning is utilizing penetration testing tools that give the Hacker information about how a network is set up. Through a scan the Ethical Hacker can find active hosts to target, open ports to target and general information about the network.

Scanning can be completed through tools like Network mapper AKA NMAP. NMAP is a powerful tool that aids ethical hackers in mapping a network and finding the information needed to conduct the next phase “Gaining Access”.

Scanning will also be done to find specific vulnerabilities in a target system. These vulnerabilities can be caused by any aspect of the security measures on the target system. Vulnerabilities are found through Vulnerability Scanners like Metasploit’s in-built scanner.

3. Gaining Access

Gaining Access relies on information found through scanning. In the scanning phase an Ethical Hacker would have found information about a target. Specifically, Ip addresses, Open ports, Operating System (OS), and OS version. This information is used in Metasploit.

Metasploit is used to create payloads (read more about payloads). These payloads are used to exploit specific vulnerabilities found in the system targeted in the Scanning Phase. Once the Vulnerability has been exploited with the payload, the Ethical Hacker will have access to the system.

4. Maintaining Access

The Ethical Hacker won’t stop at one target system. They will maintain their access by using the privileges of the target system on a network to escalate to other systems in the network. This is called Lateral Movement and occurs once a hacker is in a network. They can move from one system to another and Escalate Privileges allowing them more access to different information within the network. I.E the Network Administrators device from the Interns Device.

5. Covering Tracks

Finally, one of the most important steps for an Ethical Hacker to ensure they don’t get caught by the system administrator is covering tracks. This can be done simply by masking IP addresses with a VPN. A VPN will allow an Ethical Hacker to route their IP address to a server elsewhere in the world over an encrypted connection. This ensure that if they are detected by a firewall on the network, they are Penetration testing, it won’t get traced back to them.

Other ‘Track Covering Methods’ include port forwarding, Proxy servers, and using the escalated privileges from the previous steps to delete any traces of an attack in the Systems Log Files.


Thank you for taking the time to read and learn. At Sword and Shield Cybersecurity we aim to provide the best Cybersecurity Content for free, along with paid services in the future. You can support us by sharing these posts on social media to help your friends and family become more Cybersecurity Conscious.

Stay tuned, like and follow on social media, and sign up for our e-mail notifications as we have a YouTube Channel Coming in the future, as well as more posts.

Like/Follow/Subscribe:

Share:

Share this post


Discover more from Sword and Shield Cybersecurity

Subscribe now to keep reading and get access to the full archive.

Continue reading