Skip to Content
Kali Linux Penetration Testing Bible
book

Kali Linux Penetration Testing Bible

by Gus Khawaja
June 2021
Intermediate to advanced content levelIntermediate to advanced
512 pages
11h 12m
English
Wiley
Content preview from Kali Linux Penetration Testing Bible

CHAPTER 14Reporting

Recently, I was handed a penetration testing report prepared by a third‐party company. This company hired some consultants to pentest one of the newly deployed web applications in the production environment. The report was a copy‐and‐paste from another security scanner (e.g., Burp Suite, Nessus, etc.) report and full of misestimated severities. I'm telling you this story because if you're the best penetration tester in the world and you don't know how to make a report, then all your efforts will be for nothing. A report is your reputation, and it shows what your level of professionalism is.

In this chapter, you will mainly learn how to do the following:

  • Present reports to your clients/employers
  • Score the severity of your findings

Overview of Reports in Penetration Testing

A report is not just about the look and feel. Some individuals think an excellent report is filled with words. A good report will have the following criteria:

  • Accurate vulnerabilities severity scoring (not exaggerating the severity of a vulnerability)
  • No false positives
  • Evidence (e.g., screenshots, or PoC) and not just links or definitions
  • Instructions for how to remediate the flaw. This is where a security professional will shine. A clear definition of how to fix the issue is a turning point in your reports. (I've seen a lot of reports where the remediation part is just a link to OWASP, a CVE reference, etc.)
  • Be clear and not too wordy
  • Must be divided into two reports:
    • A technical ...
Become an O’Reilly member and get unlimited access to this title plus top books and audiobooks from O’Reilly and nearly 200 top publishers, thousands of courses curated by job role, 150+ live events each month,
and much more.
Start your free trial

You might also like

Mastering Kali Linux for Advanced Penetration Testing - Fourth Edition

Mastering Kali Linux for Advanced Penetration Testing - Fourth Edition

Vijay Kumar Velu
Web Penetration Testing with Kali Linux - Third Edition

Web Penetration Testing with Kali Linux - Third Edition

Daniel W. Dieterle, Gilberto Najera-Gutierrez, Juned Ahmed Ansari

Publisher Resources

ISBN: 9781119719083Purchase Link