A financial institution is performing a penetration test on its core banking application. The scope of work explicitly states that the penetration tester is NOT allowed to cause any service disruption or data corruption. During the test, the tester identifies a critical SQL injection vulnerability that could lead to full database compromise. What is the MOST appropriate action for the penetration tester to take?
- AProceed with full exploitation but ensure all actions are reversible and data is not altered.
- BIgnore the vulnerability as exploitation might violate the 'no disruption' clause.
- CDocument the vulnerability and its potential impact, then immediately inform the client without attempting full exploitation.
- DExploit the vulnerability to exfiltrate a small amount of sensitive data to prove impact.
Show answer & explanationAnswer & explanation
Correct answer: C. Document the vulnerability and its potential impact, then immediately inform the client without attempting full exploitation.
The primary constraint is 'NOT allowed to cause any service disruption or data corruption.' While proving impact is crucial in pen testing, attempting full exploitation of a critical SQL injection carries a very high risk of violating these explicit rules, even with careful measures. Documenting the finding and its potential severe impact, then immediately informing the client, is the safest and most ethical approach when facing such strict constraints on a critical system.
Why the other options are wrong
- A. Full exploitation, even with reversibility in mind, carries a significant risk of unintended disruption or corruption, especially with SQL injection.
- B. Ignoring a critical vulnerability would be a failure of the penetration test's purpose and unethical.
- D. Exfiltrating sensitive data, even a small amount, could be considered data corruption or a policy violation.
Penetration Test Scope Limitations
Explicit rules and boundaries defined in the 'Rules of Engagement' for a penetration test, outlining what is and is not permitted, often including restrictions on exploitation impact.
- Crucial for ethical and legal compliance.
- Must be strictly adhered to by testers.
- Often includes 'no disruption' or 'no data modification' clauses for critical systems.
Memory trick: Scope is king, avoid the fling.