Automatically translated.View original post

👾Wanna Be A Hacker! | Is Penetration Tester? 👾

I believe that as a child, there are many people who want to be a Hacker (right? Hahahaha)

In Episode 1, cybersecurity is the closest career to Hacker, or Hacker, it's still called Hacker. This career is a redteam, which is "Penetration Tester" or "Pentester," and it's also one of cybersec's. But wait 🖐🏻, let me say that this career is not a pen test like some people call it. 😭😭 Tease 😆

👾, what does Pentester do??

In fact, the main function of pentester is "pen testing," or it can be easily called a hack, haha 😆, but it is a scope hacking that is allowed to do so. The goal is to find Vulnerability in the system. Why find it to notify the vulnerability found in the system to the organization or the owner of the system so that he can prevent and correct it before being hacker?

(From now on, let me call it "penetration.")

👾 usually there are many types of pentest, such as:

1.Web Application Pentation:

The real thing is to hack into the web application.

2. Mobile application Pentesting:

Mobile application penetration

3.API Pentation Penetration:

API security test

* There's actually more, like the Network, OT / IOT *

👾 the guiding model of system penetration, there are 3 varieties together.

1.Black Box Testing: It is a penetration of the system. The tester does not know any information about the system (Zero-Knowledge).

2. Gray Box Testing: It is a hack. The tester knows some of the system information, such as user travel, user accounts.

3.White Box Testing: It is a hack. The tester knows all the information of the system, including the source code of the system.

😶‍🌫️ this post, I would like to put the brakes on it first, hahahahaha. There are also many things that are not mentioned, such as Methodology, Pentest Method, Skills to Know, Tools, Redteaming, and more. Please keep it as an EP. 🤓 If you accidentally give me any wrong information, I'm sorry. (Comment to help fix it) Thank you to everyone who came to read 🥺🙏🏻. See you again.

# Cybersecurity # pentest # Pentesting # redteam # hacker# hacking

2025/8/20 Edited to

... Read moreถ้ากำลังค้นหา “pentest คืออะไร” หรือ “pentester คืออะไร” แบบอยากได้คำตอบที่อ่านแล้วเห็นภาพเลย เราขอเล่ามุมที่เจอบ่อย ๆ เวลาเริ่มทำความเข้าใจสายนี้นะครับ Pentest (Penetration Testing) คือการ “ทดสอบเจาะระบบ” แบบได้รับอนุญาต เพื่อหาช่องโหว่ (vulnerability) ก่อนที่คนไม่หวังดีจะมาเจาะจริง ๆ จุดสำคัญมากคือทำตาม scope/ขอบเขตที่ตกลงกันไว้ เช่น อนุญาตให้ทดสอบแค่เว็บบางโดเมน บางฟีเจอร์ หรือบางช่วงเวลาเท่านั้น อันนี้แยก pentester ออกจากการแฮกผิดกฎหมายชัดเจน แล้ว Pentester ทำอะไรใน 1 งานจริง ๆ? - คุยขอบเขตงาน: เป้าหมายคืออะไร ระบบอะไรห้ามแตะ วิธีรายงาน และเกณฑ์ความเสี่ยง - เก็บข้อมูล (recon): สำรวจพื้นผิวการโจมตี เช่น endpoint, subdomain, เวอร์ชันบริการ - ทดสอบช่องโหว่ตามประเภทระบบ: เว็บ/มือถือ/API (ตามที่บทความพูดไว้) บางที่รวม network หรือ cloud ด้วย - พิสูจน์ผลกระทบ (proof of concept): ทำให้เห็นว่าช่องโหว่ส่งผลอะไรได้จริง แต่ต้องไม่ทำให้ระบบล่ม - ทำรายงาน: อธิบาย “พบอะไร-เสี่ยงแค่ไหน-แก้ยังไง” และมักมีรอบ retest หลังแก้ไข สิ่งที่คนค้นหา “penetration คืออะไร” มักสับสนกับคำว่า penetration เฉย ๆ ใน cyber มันหมายถึงการ “เจาะ/ทะลวง” เพื่อทดสอบการป้องกัน ไม่ได้หมายถึงทำลายระบบ จุดประสงค์คือช่วยให้องค์กรปิดรูรั่วให้ทัน ทักษะที่มือใหม่ควรรู้ (ถ้าอยากไปทาง pentester) - พื้นฐานเว็บ: HTTP/HTTPS, cookie/session, auth, CORS, file upload - พื้นฐานเครือข่าย: TCP/IP, DNS, ports, proxy - การอ่านโค้ดและตรรกะ: ไม่ต้องเทพตั้งแต่วันแรก แต่ควรอ่าน flow ได้ - การเขียนรายงานและสื่อสาร: ทำให้ทีม dev แก้ได้เร็ว สำคัญพอ ๆ กับการหาเจอ เครื่องมือที่มักเห็นในสายนี้ (ขอพูดแบบภาพรวม) - Proxy สำหรับดู request/response และทดสอบเว็บ - เครื่องมือสแกนช่องโหว่เพื่อช่วยไล่จุดเสี่ยงเบื้องต้น - เครื่องมือทดสอบ API และจัดการคอลเลกชัน request (สุดท้ายยังไง “ความเข้าใจระบบ” สำคัญกว่าเครื่องมือเสมอ) เลือก Black/Gray/White box แบบไหนดี? - Black box เหมาะกับการจำลองผู้โจมตีภายนอก - Gray box มักคุ้มค่าเพราะมี account/ข้อมูลบางส่วน ทำให้เจอเชิงตรรกะได้เร็ว - White box ดีมากเวลาต้องการความครอบคลุมและลดการเดา โดยเฉพาะถ้าได้ดู source code ถ้าคุณเคยเห็นภาพแนว “คนใส่ฮู้ดกับโค้ดไหล ๆ” แล้วคิดว่า pentester ต้องลึกลับตลอด จริง ๆ งานประจำวันคืออ่านระบบ วิเคราะห์ความเสี่ยง และสรุปให้คนแก้ได้ชัดเจนมาก ๆ ครับ