arrow_backফিল্ড নোটে ফিরুন
OFFENSIVE প্রকাশিত 18 Jul 2026

Penetration Testing আসলে কী?

Penetration testing এর একটি ব্যবহারিক বিশ্লেষণ: এটি কী, কীভাবে engagement চলে, এবং vulnerability scan থেকে এটিকে কী আলাদা করে।

Penetration testing হল একটি signed agreement এর অধীনে একটি system, network, বা application এর বিরুদ্ধে বাস্তব আক্রমণের অনুকরণ করার অনুশীলন, যার লক্ষ্য exploitable weaknesses খুঁজে বের করা যাতে অনুমোদিত না হয়ে কেউ এটি করতে না পারে। এটি একটি নিয়ন্ত্রিত, সময়-সীমাবদ্ধ ব্যায়াম যা একটি রিপোর্টে শেষ হয়, কোন খোলা-শেষ hacking spree নয়।

Pentesting এবং vulnerability scanning এর মধ্যে পার্থক্য

Nessus বা OpenVAS এর মতো একটি vulnerability scanner একটি target কে known signatures এর একটি database এর বিপরীতে পরীক্ষা করে এবং আপনাকে সম্ভাব্য সমস্যাগুলির একটি তালিকা দেয়, যার বেশিরভাগের manual verification প্রয়োজন। একটি pentest আরও এগিয়ে যায়: tester আসলে findings কে exploit করার চেষ্টা করে, সেগুলি একসাথে chain করে, এবং বাস্তব impact প্রদর্শন করে। Scanning আপনাকে বলে যে একটি port খোলা এবং একটি service version পুরানো দেখাচ্ছে। Pentesting আপনাকে বলে যে সেই পুরানো service টি একটি shell পেতে ব্যবহার করা যায়, এবং সেই shell থেকে আপনি domain controller এ pivot করতে পারেন।

সেই distinction রিপোর্টিং এর জন্যও গুরুত্বপূর্ণ। একটি scan report একটি তালিকা। একটি pentest report একটি গল্প evidence সহ: screenshots, command output, এবং initial foothold থেকে যাই করা হোক না কেন সম্মত objective (data access, domain admin, ইত্যাদি) পর্যন্ত attack path এর একটি walkthrough।

একটি engagement কীভাবে scoped হয়

কোন testing শুরু হওয়ার আগে, client এবং tester rules of engagement এ সম্মত হন: কি scope এ আছে (specific IP ranges, domains, applications), কি off-limits (production databases, third-party systems যা client এর মালিকানায় নেই), testing windows, এবং emergency contacts যদি কিছু ভেঙে যায়। এটি একটি signed authorization letter বা contract এ documented। সেই authorization ছাড়া, একই technical work একটি crime US Computer Fraud and Abuse Act বা UK Computer Misuse Act এর মতো laws এর অধীনে।

Engagements সাধারণত categorized হয় কত তথ্য tester এর সাথে শুরু হয়:

  • Black box — tester একটি target এবং আর কিছু নয় পায়, একটি বাইরের attacker এর অনুকরণ করে শূন্য prior knowledge সহ।
  • Gray box — tester কিছু তথ্য পায়, একটি user account বা network diagram এর মতো, একটি malicious insider বা compromised credential scenario এর অনুরূপ।
  • White box — tester এর source code, architecture docs, এবং credentials এ full access আছে, deep application-level testing এর জন্য উপযোগী।

একটি typical methodology কেমন দেখায়

বেশিরভাগ pentests loosely PTES (Penetration Testing Execution Standard) বা NIST SP 800-115 এর phases এর কাছাকাছি একটি structure অনুসরণ করে:

  1. Reconnaissance — passive এবং active information gathering। Tools যেমন theHarvester, amass, বা plain Google dorking exposed subdomains এবং employee emails এর জন্য।
  2. Scanning and enumeration — target range এর বিপরীতে nmap -sC -sV, web apps এ gobuster বা ffuf সহ directory brute-forcing, internal networks এ enum4linux সহ SMB enumeration।
  3. Exploitation — known CVEs, misconfigurations, weak credentials, বা custom payloads ব্যবহার করে initial access gain করা। এটি একটি Metasploit module, একটি crafted SQL injection payload, বা একটি phishing email বা malicious macro সহ হতে পারে।
  4. Post-exploitation — একবার আপনার foothold থাকলে, বাস্তব কাজ শুরু হয়: privilege escalation, lateral movement, Mimikatz বা secretsdump.py এর মতো tools সহ credential harvesting, এবং figure out করা access actually কতদূর যায়।
  5. Reporting — CVSS scores, reproduction steps, evidence, এবং remediation guidance সহ findings লেখা যা client এর engineering team act করতে পারে।

Types of pentests যা আপনি চালাবেন

Network pentests internal বা external infrastructure target করে — servers, firewalls, routers। Web application pentests OWASP Top 10 এ জিনিসগুলিতে focus করে: injection flaws, broken authentication, insecure deserialization। Mobile app pentests APK/IPA files, API endpoints, এবং local storage এ dig করে। Wireless pentests Wi-Fi security test করে (WPA2/3 handshake capture, rogue access points)। Physical এবং social engineering pentests test করে কিনা কেউ একটি building এ walk করতে পারে বা একজন employee কে credentials hand over করতে convince করতে পারে, কোন code প্রয়োজন নেই।

কেন companies আসলে এর জন্য pay করে

Bugs খুঁজে পাওয়ার বাইরে, pentests compliance requirements পূরণ করে। PCI DSS card data handle করা যে কাউকে annual penetration tests প্রয়োজন। SOC 2 এবং ISO 27001 audits প্রায়ই regular testing এর evidence আশা করে। তবে সৎ কারণ good security teams pentests commission করে শুধু checkbox নয় — এটি যে automated scanners business logic flaws, chained low-severity issues, এবং skilled human যা creative exploitation খুঁজে পায় miss করে। একটি scanner লক্ষ্য করবে না যে একটি URL এ order ID পরিবর্তন করলে আপনি অন্য কারো invoice দেখতে পারেন। একটি tester করবে।

এই field এ পায়ের চিহ্ন রাখা

আপনি যদি pentesting কে একটি career হিসাবে লক্ষ্য করছেন, hands-on practice সার্টিফিকেশন একা এর চেয়ে বেশি গুরুত্বপূর্ণ। HackTheBox এবং TryHackMe এর মতো platforms muscle memory build করে; OSCP এর মতো certifications এটি validate করে। Source code পড়া শিখুন, byte level এ HTTP আসলে কীভাবে কাজ করে তা বুঝুন, এবং flashy tools নিয়ে চিন্তা করার আগে একটি Linux terminal এর সাথে comfortable হন।

যদি এই rundown useful ছিল, Korra Studio Offensive track এ আরও segments আছে যা specific exploitation techniques, tool walkthroughs, এবং lab-based practice কভার করে যা আপনি follow করতে পারেন।

AI সহায়তায় লেখা, পর্যালোচনা ও প্রকাশ করেছেন Michal Pilch (CISSP), Korra Studio।

আরও এগোতে প্রস্তুত?

এটি Korra Studio-র নলেজ বেস থেকে একটি নোট — প্ল্যাটফর্মটি প্রতিটি বিষয়কে ১-এর-সাথে-১ মেন্টরিংয়ের সাথে জুড়ে দেয়।

বিনামূল্যে শুরু করুনarrow_forward