Standards and Compliance: The assessment and reporting will align with TSE, BDDK, ISO/IEC 27001:2017, ISAE 3402, NIST, PCI DSS, SoX/COBIT, and SAS 70 standards. All evaluations will ensure adherence to OWASP and OSSTMM standards in line with Esbilgi Security Audit techniques.
Penetration Testing Scope:
All servers and network devices under review will be subjected to penetration testing to identify vulnerabilities in compliance with OWASP, OSSTMM, and related security standards.
- Services, applications, and protocols, including but not limited to HTTP, DNS, SMTP, POP3, FTP, IMAP, TELNET, SSH, and SSL, will be manually analyzed for vulnerabilities.
- Configuration Errors and Weaknesses:
All configuration errors and deficiencies detectable from both local and remote networks will be identified.
- Web Application Security:
Comprehensive security testing of web-based applications and connected databases will be conducted.
- All tests will adhere to OWASP, OSSTMM, BDDK, and TSE standards and be executed according to Esbilgi Security Audit methodologies.
- Manual assessments will evaluate against web-based attack techniques, including:
- CSS (Cross-Site Scripting)
- XSS (Cross-Site Scripting)
- SQL Injection
- CSRF (Cross-Site Request Forgery)
- Authentication and session hijacking
- Character filtering issues
- Parameter tampering
- Cookie manipulation
- Privilege Escalation and User Role Abuse:
The security of the system will be assessed for privilege escalation risks, examining interactions between users, databases, and servers.
- All vulnerabilities associated with user-to-server interactions will be manually verified, both from the perspective of a regular visitor and users with elevated access rights.