<!DOCTYPE article PUBLIC "-//NLM//DTD JATS (Z39.96) Journal Archiving and Interchange DTD v1.0 20120330//EN" "JATS-archivearticle1.dtd">
<article xmlns:xlink="http://www.w3.org/1999/xlink">
  <front>
    <journal-meta />
    <article-meta>
      <contrib-group>
        <contrib contrib-type="author">
          <string-name>Alexander V. Dorofeev</string-name>
          <xref ref-type="aff" rid="aff0">0</xref>
          <xref ref-type="aff" rid="aff1">1</xref>
        </contrib>
        <contrib contrib-type="author">
          <string-name>Yrii V. Rautkin</string-name>
          <xref ref-type="aff" rid="aff0">0</xref>
          <xref ref-type="aff" rid="aff1">1</xref>
        </contrib>
        <aff id="aff0">
          <label>0</label>
          <institution>Fedorova Institute of Applied Geophysics Moscow</institution>
          ,
          <country country="RU">Russia</country>
        </aff>
        <aff id="aff1">
          <label>1</label>
          <institution>Training Center Echelon</institution>
          ,
          <addr-line>NPO Moscow</addr-line>
          ,
          <country country="RU">Russia</country>
        </aff>
      </contrib-group>
      <fpage>49</fpage>
      <lpage>53</lpage>
      <abstract>
        <p>-The article is concerned with the procedure for ethical testing of computer systems' resource security. The capabilities of the Metasploit Framework testing tool are considered. The key “pain points” of modern corporate systems are identified. The general scheme and the security testing procedure are suggested. Vulnerability collection phases, checking the probability of exploiting discovered vulnerabilities, influence zone extension and privilege escalation are discussed in detail. It is shown that the proposed approach allows the maximum number of vulnerabilities to be detected.</p>
      </abstract>
      <kwd-group>
        <kwd>information security</kwd>
        <kwd>security testing</kwd>
        <kwd>penetration testing</kwd>
        <kwd>exploit</kwd>
        <kwd>Metasploit Framework</kwd>
        <kwd>Scanner-VS</kwd>
      </kwd-group>
    </article-meta>
  </front>
  <body>
    <sec id="sec-1">
      <title>-</title>
      <p>INTRODUCTION</p>
      <p>
        Very few experts specializing in security testing have ever
faced the situation when they were unable to fully compromise
a network in the course of internal penetration testing [7]. The
reasons for ethical hackers to succeed are trite: weak passwords,
no critical security updates, configuration errors [
        <xref ref-type="bibr" rid="ref11 ref13">11, 13</xref>
        ]. This
brings up the questions: if vulnerability causes are so trite, could
they devise a list of key tests to be carried out independently by
a system administrator and is there a tool that could help him
do it? The tool of our choice is Metasploit Framework that can
be installed by the user or advantage can be taken of what is
offered by the Scanner VS complex [
        <xref ref-type="bibr" rid="ref10 ref15 ref16 ref19">6, 10, 15, 16, 21</xref>
        ]. Note
that it is not our intention in this article to focus on testing
security of web applications as these represent a separate testing
area [
        <xref ref-type="bibr" rid="ref2">2</xref>
        ].
      </p>
      <p>Before coming to grips with engineering problems, we
should understand what may interest potential attackers and
how they will act.</p>
      <p>II.</p>
      <p>INFORMATION ATTACKERS ARE INTERESTED IN</p>
      <p>As a rule, cyber-attackers are motivated by money earned
on successful hacking (theft of funds, blackmail, carrying out
orders for a party concerned) or by their own curiosity and
willing to check what they are capable of. Attackers may aim at
whatever permitting them either to steal or earn. Apart from any
system operated by an organization, their aim may be folders
on file servers and documents on users’ workstations.</p>
      <p>III.</p>
      <p>HIGH RISK AREAS</p>
      <p>The main reason why somebody fails to update security or
change a default password is a lack of responsible and proper
1.
2.
3.
4.
5.
6.</p>
      <p>METASPLOIT FRAMEWORK GENERAL HANDLING</p>
      <p>PROCEDURE</p>
      <p>As we have chosen Metasploit Framework as a security
testing tool, we need to describe the basic algorithm of handling
its constituent modules.</p>
      <p>The module is handled by performing the following steps:
Search for a suitable module using the search command
or Google.</p>
      <p>Select the module by the use command.</p>
      <p>View the chosen module settings using show options or
show advanced commands.</p>
      <p>Specify a specific setting using the set command.</p>
      <p>Set verbose output using the set verbose true command.
Run the module using the run command.</p>
    </sec>
    <sec id="sec-2">
      <title>GENERAL SECURITY TESTING PROCEDURE</title>
      <p>
        Security testing of information systems is often a creative
process that, nevertheless, can and should be structured to
obtain comparable and complete testing results [
        <xref ref-type="bibr" rid="ref1 ref4 ref5">1, 4, 5, 8, 9</xref>
        ].
      </p>
      <p>
        The following sources provide a good description of
security testing methodologies [
        <xref ref-type="bibr" rid="ref17 ref20 ref3">3, 17, 18, 22</xref>
        ]:




      </p>
      <p>Penetration Testing Execution Standard (PTES);
Open Source Security Testing Methodology Manual
(OSSTMM);
Technical Guide to Information Security Testing and
Assessment (NIST SP 800-115);</p>
      <p>OWASP Testing Guide.</p>
      <p>PTES offers a detailed structure of the tasks to be tackled
during security testing and exemplifies the use of various tools,
while giving hardly any details of Metasploit Framework.
OSSTM is largely intended for information security managers
and contains a very restricted amount of technical information.
NIST SP 800-115 was adopted in 2008 and only partially
covers modern approaches to security testing. OWASP Testing
Guide is only concerned with security testing of web
applications and contains a detailed and structured description
of testing methods and a variety of tool options.</p>
      <p>The following diagram (figure 1) depicts a generalized
structure of the proposed security testing process.</p>
      <p>VI. INFLUENCE ZONE EXTENSION AND PRIVILEGE</p>
      <p>ESCALATION</p>
      <sec id="sec-2-1">
        <title>Phase 1. Task definition</title>
        <p>Security testing of any IT infrastructures starts with task
definition. In our case we will confine ourselves to searching
for the maximum number of real vulnerabilities that may be
exploited by potential attackers having physical access to an
organization’s computer network.</p>
      </sec>
      <sec id="sec-2-2">
        <title>Phase 2. Information gathering and target search</title>
        <p>In order to perform security testing, experts are provided
with access to a company’s network. In the course of
preliminary information gathering, they will scan subsystems,
identify computers’ names, and find public network locations
and critical resources.</p>
        <sec id="sec-2-2-1">
          <title>Port scanning</title>
          <p>Ports can be scanned using the “db_nmap – wrapping
utility” command for nmap in Metasploit Framework, which
allows scanning results to be saved to the database.</p>
          <p>It should be borne in mind that if we do not specify the port
range explicitly, 1,000 most commonly used ports will be
scanned; if we specify the keys -F or -p-, 100 or 65,535 ports
will be scanned, respectively.</p>
          <p>What we can learn from port scanning results is not only
which network ports are open, but also service versions (if the
key “-sV” has been used) as well as the presumable OS version
(key “-О”) and the equipment manufacturer by the MAC
address.</p>
          <p>The completed port scanning shows which IP addresses
hide domain controllers, DBMS servers, WEB, network
equipment and workstations.</p>
        </sec>
        <sec id="sec-2-2-2">
          <title>Search for public network locations</title>
          <p>As discussed above, public network locations may contain
a wealth of information useful for an attacker. It makes sense to
search for such locations both with an anonymous credential
(blank login/blank password) and a normal user’s credential.</p>
          <p>The “auxiliary/scanner/smb/smb_enumshares” and
“auxiliary/scanner/nfs/nfsmount” modules should be used to
search for SMB and NFS resources, respectively.</p>
        </sec>
        <sec id="sec-2-2-3">
          <title>DBMS search</title>
          <p>It is worth using the “auxiliary/scanner/mssql/mssql_ping”
module to search for DBMS MS SQL as it helps not only find
DBMS servers by the open UDP port 1434, but also identify the
TCP port, via which the database is waiting to be connected.</p>
        </sec>
        <sec id="sec-2-2-4">
          <title>NetBIOS name definition</title>
          <p>It is often useful to define NetBIOS names (as they may also
contain helpful information, for example, on which system a
subsystem pertains to) by taking advantage of the
auxiliary/scanner/netbios/nbname module.</p>
        </sec>
      </sec>
      <sec id="sec-2-3">
        <title>Phase 3. Vulnerability Search</title>
        <p>The table below lists the key vulnerability detection methods.</p>
        <p>From this list, Metasploit Framework implements modules
for the methods “Exploitation attempt”, “Fuzzing” and partially
“Identifying vulnerabilities by product version”.</p>
        <p>The reason why “Identifying vulnerabilities by product
version” is not fully implemented in Metasploit Framework is
because it primarily uses vulnerability scanners, such as one
from Scanner VS, to automatically detect potential
vulnerabilities. Note, however, that some exploitation modules
in Metasploit Framework support the “check” method that can
be used to identify a vulnerability before its exploitation.</p>
        <p>Data on network service versions obtained at the port
scanning phase is suitable for manual vulnerability analysis. A
security tester generates Google search queries of the "service
Examples
Identifying a product
version by the network
service banner and
browsing for
information on the
known vulnerabilities of
the product
Attempting to connect
to the Windows system
through a zero session
and unloading the list of
user credentials
Starting an exploit
against a network
service without its prior
analysis for conformity
to the service
Attempting to intercept
traffic by means of ARP
poisoning
Analyzing the Windows
register contents
Disassembling an
executable file to study
the logic of program
execution and data
handling
Searching the php code
for fragments related to
filtration of data entered
by the user to get
around filtration rules
and introduce
JavaScript code
Entry into a web form
of SQL queries and
analysis of received
error messages
version +vulnerability +exploit” type to find pages of
specialized resources describing vulnerabilities and exploits.</p>
        <p>Metasploit Framework contains a set of fuzzing modules to
execute protocols, such as dns, ftp, http, smb, smtp, ssh etc.
These modules are available at auxiliary/fuzzers/.</p>
        <p>It should be noted that, since security testing projects are
normally restricted to a period of 2-3 weeks, security testers
confine themselves to automated and manual search of
vulnerabilities by version and to exploitation attempts.</p>
      </sec>
      <sec id="sec-2-4">
        <title>Phase 4. Exploitation and execution of attacks</title>
        <p>In order to exploit vulnerabilities, network services and
applied software make use of exploits from Metasploit
Framework exploit section. The current number of Metasploit
Framework’s ready-to-use exploits is nearing 2,000.</p>
        <p>In order to find suitable exploits, security testers utilize the
“search” command by the CVE code, service name or version
(for example, search vsftpd).</p>
        <p>When exploiting a vulnerability, the so-called payload is to
be specified. The payload is a code run on a compromised
machine. There are a variety of payloads in Metasploit
Framework, such as a remote command line, creating a
credential, booting a remote administration system etc. Using
the remote command line is often the best choice. Metasploit
Framework has an extended command line version,
Meterpreter, which is now particularly popular with testers.</p>
        <sec id="sec-2-4-1">
          <title>Password brute forcing</title>
          <p>Password brute forcing has been the most dangerous attack
over decades. Metasploit Framework contains a lot of modules
designed to execute such attacks. The table below lists the
modules that experts typically come across in security testing.</p>
        </sec>
        <sec id="sec-2-4-2">
          <title>ARP-poisoning</title>
          <p>When executing such an attack, the attacker seeks to
“poison” ARP tables of two subsystems, the traffic between
which he wants to intercept. An attack is often undertaken
against the workstation of a particular user (system
administrator, chief accountant etc.) and a domain controller or
router. Once ARP tables are poisoned, both victim subsystems
share network packets via the attacker’s computer. Having run
a sniffer, the attacker captures the data of interest, for example,
sessions of authentication with password hashes.</p>
          <p>An ARP poisoning attack in Metasploit Framework can be
executed by making use of the
“auxiliary/spoof/arp/arp_poisoning” module.</p>
        </sec>
        <sec id="sec-2-4-3">
          <title>Pass-the-hash</title>
          <p>Successful authorization when executing the NTLM
protocol does not require knowing the password – it is enough
to have the password hash and credential name. Any operating
system using the NTLM protocol can be susceptible to this
vulnerability.</p>
          <p>A pass-the-hash attack can be executed
“exploit/windows/smb/psexec” module.
using the</p>
          <p>This security testing phase provides us with a list of
vulnerabilities that can be exploited by attackers remotely. The
exploits run and attacks executed have provided us with access
to various systems and with information about compromised
credentials.</p>
          <p>Testers collect screenshots confirming access as evidence of
successful penetration.</p>
        </sec>
      </sec>
      <sec id="sec-2-5">
        <title>Phase 5. Influence zone extension and privilege escalation</title>
        <p>The existing access to a system often allows it to be
extended to other systems. Privilege escalation permitting a
normal user to become an administrator is also possible
sometimes.</p>
        <p>Let us consider two standard situations that a tester should
be aware of to make security testing easier.</p>
        <sec id="sec-2-5-1">
          <title>Lazy users making use of identical passwords</title>
          <p>Users like utilizing identical passwords in different systems,
so it is worth checking once selected pairs “login:password” in
all accessible systems.</p>
        </sec>
        <sec id="sec-2-5-2">
          <title>Lazy administrators forgetting to delete critical data from the test environment</title>
          <p>Serious systems implemented by major companies normally
have a test environment used to try out modifications, train
users etc. Test environments are often created by restoring from
production backups. Because they are test environments,
administrator sometimes fail to pay due attention to information
security issues. For example, they may create an administrator’s
credential with an easily guessed password or fail to set critical
OS updates. Upon receiving access to a test environment,
security testers unload user data (logins/password hashes) that
are largely consistent with those employed in a production
system.






</p>
        </sec>
        <sec id="sec-2-5-3">
          <title>Post-exploitation modules in Metasploit Framework</title>
          <p>Metasploit Framework has a set of so-called
postexploitation modules designed to perform the following tasks
for access extension and privilege escalation:</p>
        </sec>
      </sec>
    </sec>
    <sec id="sec-3">
      <title>Searching for suitable local exploits</title>
      <p>(post/multi/recon/local_exploit_suggester);
Running a keylogger
(post/windows/capture/keylog_recorder);
Gathering credentials and hashes
(post/windows/gather/credentials/credential_collector)
etc.</p>
      <p>With this step performed, security testers obtain maximum
access and pinpoint actual local vulnerabilities.</p>
      <sec id="sec-3-1">
        <title>Phase 6. Report development</title>
        <p>The outcome of security testing is a report on discovered
vulnerabilities. The report’s key component is information on
vulnerabilities, which is normally provided to the customer in
the structured form:</p>
        <p>Detection – information on vulnerability name and codes
and a list of vulnerability-prone subsystems.</p>
        <p>Exploitation – screenshots and logs demonstrating
vulnerability exploitation;
Risk – what vulnerability exploitation may result in;
Recommendations – technical and organizational
recommendations on elimination of vulnerabilities.</p>
        <p>Since Metasploit Framework has no security testing report
generation feature, the report is developed by testers.</p>
        <p>VII.</p>
      </sec>
    </sec>
    <sec id="sec-4">
      <title>CONCLUSION</title>
      <p>We have considered a comprehensive approach to security
testing, which can be implemented through Metasploit
Framework. Metasploit Framework is an aid in completing the
key phases of security testing, except for automated
vulnerability search and report generation. These phases,
however, are implemented in the Scanner VS complex that
comprises Metasploit Framework. When used in conjunction,
the described methodology, Scanner VS and Metasploit
Framework help discover the maximum number of actual
vulnerabilities.</p>
      <p>Methodology</p>
      <p>Manual.</p>
      <p>Online
[18] OWASP Testing Guide. Online
https://www.owasp.org/index.php/OWASP_Testing_Guide_v4_Table_o
f_Contents
[19] Penetration testing execution standard. Online
standard.org</p>
    </sec>
  </body>
  <back>
    <ref-list>
      <ref id="ref1">
        <mixed-citation>
          [1]
          <string-name>
            <surname>Scaner-VS</surname>
          </string-name>
          . http://scaner-vs.ru/trial/
        </mixed-citation>
      </ref>
      <ref id="ref2">
        <mixed-citation>
          [2]
          <string-name>
            <surname>Abraham</surname>
            <given-names>K</given-names>
          </string-name>
          <string-name>
            <surname>White. Hacking</surname>
            : The Underground Guide to Computer Hacking, Including Wireless Networks, Security, Windows, Kali Linux and
            <given-names>Penetration</given-names>
          </string-name>
          <string-name>
            <surname>Testing</surname>
          </string-name>
          . - CreateSpace
          <string-name>
            <surname>Independent Publishing Platform</surname>
          </string-name>
          ,
          <year>2017</year>
          . 230 p.
        </mixed-citation>
      </ref>
      <ref id="ref3">
        <mixed-citation>
          [3]
          <string-name>
            <surname>Barabanov</surname>
            <given-names>A.V.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Lavrov</surname>
            <given-names>A.I.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Markov</surname>
            <given-names>A.S.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Polotnyanschikov</surname>
            <given-names>I.A.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Tsirlov</surname>
            <given-names>V.L.</given-names>
          </string-name>
          <article-title>The study into cross-site request forgery attacks within the framework of analysis of software vulnerabilities</article-title>
          .
          <source>Trudy ISP RAN/Proc. ISP RAS</source>
          , vol.
          <volume>29</volume>
          , issue 5,
          <year>2017</year>
          , pp.
          <fpage>7</fpage>
          -
          <lpage>18</lpage>
          . DOI:
          <volume>10</volume>
          .15514/ISPRAS-2017-
          <volume>29</volume>
          (
          <issue>5</issue>
          )-
          <fpage>1</fpage>
          .
        </mixed-citation>
      </ref>
      <ref id="ref4">
        <mixed-citation>
          [4]
          <string-name>
            <given-names>Chris</given-names>
            <surname>McNab. Network Security Assessment: Know Your Network. - O'Reilly Media</surname>
          </string-name>
          ,
          <year>2017</year>
          . 508 p.
        </mixed-citation>
      </ref>
      <ref id="ref5">
        <mixed-citation>
          [5]
          <string-name>
            <surname>Corey</surname>
            <given-names>P.</given-names>
          </string-name>
          <string-name>
            <surname>Schultz</surname>
            ,
            <given-names>Bob</given-names>
          </string-name>
          <string-name>
            <surname>Perciaccante. Kali Linux Cookbook - Second Edition</surname>
          </string-name>
          :
          <article-title>Effective penetration testing solutions</article-title>
          . - Packt
          <string-name>
            <surname>Publishing</surname>
          </string-name>
          ,
          <year>2017</year>
          . 438 p.
        </mixed-citation>
      </ref>
      <ref id="ref6">
        <mixed-citation>
          <string-name>
            <surname>Daniel</surname>
            <given-names>W.</given-names>
          </string-name>
          <string-name>
            <surname>Dieterle</surname>
          </string-name>
          .
          <article-title>Basic Security Testing with Kali Linux 2</article-title>
          .
          <string-name>
            <surname>- CreateSpace Independent Publishing Platform</surname>
          </string-name>
          ,
          <year>2016</year>
          . 380 p.
        </mixed-citation>
      </ref>
      <ref id="ref7">
        <mixed-citation>
          <string-name>
            <given-names>David</given-names>
            <surname>Kennedy</surname>
          </string-name>
          ,
          <string-name>
            <surname>Jim O'Gorman</surname>
            ,
            <given-names>Devon</given-names>
          </string-name>
          <string-name>
            <surname>Kearns</surname>
          </string-name>
          .
          <source>Metasploit: The Penetration Tester's Guide</source>
          . - No Starch Press,
          <year>2011</year>
          . 328 p.
        </mixed-citation>
      </ref>
      <ref id="ref8">
        <mixed-citation>
          <string-name>
            <surname>Dorofeev A</surname>
          </string-name>
          .
          <article-title>Preparing for CISSP: telecommunications and network security</article-title>
          .
          <source>Voprosy kiberbezopasnosti [Cybersecurity issues]</source>
          ,
          <year>2014</year>
          , No
          <volume>4</volume>
          (
          <issue>7</issue>
          ). P.
          <volume>69</volume>
          -
          <fpage>74</fpage>
          . (In Rus).
        </mixed-citation>
      </ref>
      <ref id="ref9">
        <mixed-citation>
          <string-name>
            <given-names>Evan</given-names>
            <surname>Lane</surname>
          </string-name>
          .
          <article-title>Hacking with Python: Beginner's Guide to Ethical Hacking, Basic Security</article-title>
          , Penetration Testing, and
          <string-name>
            <given-names>Python</given-names>
            <surname>Hacking</surname>
          </string-name>
          . - CreateSpace
          <string-name>
            <surname>Independent Publishing Platform</surname>
          </string-name>
          ,
          <year>2017</year>
          . 106 p.
        </mixed-citation>
      </ref>
      <ref id="ref10">
        <mixed-citation>
          [10]
          <string-name>
            <given-names>Georgia</given-names>
            <surname>Weidman. Penetration Testing</surname>
          </string-name>
          :
          <string-name>
            <given-names>A</given-names>
            <surname>Hands-On Introduction to Hacking</surname>
          </string-name>
          . - No Starch Press,
          <year>2014</year>
          . 528 p.
        </mixed-citation>
      </ref>
      <ref id="ref11">
        <mixed-citation>
          [11]
          <string-name>
            <surname>Jessey</surname>
            <given-names>Bullock</given-names>
          </string-name>
          , Jeff T. Parker.
          <article-title>Wireshark for Security Professionals: Using Wireshark and the Metasploit Framework</article-title>
          . - John Wiley &amp; Sons,
          <year>2017</year>
          . 288 p.
        </mixed-citation>
      </ref>
      <ref id="ref12">
        <mixed-citation>
          [12]
          <string-name>
            <given-names>Josh</given-names>
            <surname>Thompsons</surname>
          </string-name>
          . Hacking: Hacking For Beginners Guide On How To Hack, Computer Hacking, And The Basics Of Ethical Hacking. - CreateSpace
          <string-name>
            <surname>Independent Publishing Platform</surname>
          </string-name>
          ,
          <year>2017</year>
          . 112 p.
        </mixed-citation>
      </ref>
      <ref id="ref13">
        <mixed-citation>
          [13]
          <string-name>
            <given-names>Joshua</given-names>
            <surname>Picolet</surname>
          </string-name>
          .
          <source>Hash Crack: Password Cracking Manual (v2.0)</source>
          .
          <source>CreateSpace Independent Publishing Platform</source>
          ,
          <year>2017</year>
          . 112 p.
        </mixed-citation>
      </ref>
      <ref id="ref14">
        <mixed-citation>
          [14]
          <string-name>
            <given-names>Matt</given-names>
            <surname>Walker. CEH Certified Ethical Hacker</surname>
          </string-name>
          All-in-One Exam Guide,
          <string-name>
            <given-names>Third</given-names>
            <surname>Edition</surname>
          </string-name>
          . - Oracle Press,
          <year>2016</year>
          . 525 p.
        </mixed-citation>
      </ref>
      <ref id="ref15">
        <mixed-citation>
          [15]
          <string-name>
            <given-names>Michael</given-names>
            <surname>Hixon</surname>
          </string-name>
          ,
          <string-name>
            <given-names>Justin</given-names>
            <surname>Hutchens. Kali Linux Network Scanning Cookbook - Second Edition</surname>
          </string-name>
          :
          <article-title>A Step-by-Step Guide Leveraging Custom Scripts and Integrated Tools in Kali Linux</article-title>
          . - Packt
          <string-name>
            <surname>Publishing</surname>
          </string-name>
          ,
          <year>2017</year>
          . 634 p.
        </mixed-citation>
      </ref>
      <ref id="ref16">
        <mixed-citation>
          [16]
          <string-name>
            <given-names>Nipun</given-names>
            <surname>Jaswal</surname>
          </string-name>
          . Metasploit Bootcamp:
          <article-title>The fastest way to learn Metasploit Paperback</article-title>
          . - Packt
          <string-name>
            <surname>Publishing</surname>
          </string-name>
          ,
          <year>2017</year>
          . 230 p.
        </mixed-citation>
      </ref>
      <ref id="ref17">
        <mixed-citation>[17] Open Source Security Testing http://www.isecom.org/research/</mixed-citation>
      </ref>
      <ref id="ref18">
        <mixed-citation>
          [20]
          <string-name>
            <given-names>Peter</given-names>
            <surname>Kim</surname>
          </string-name>
          .
          <source>The Hacker Playbook</source>
          <volume>2</volume>
          :
          <string-name>
            <given-names>Practical</given-names>
            <surname>Guide to Penetration Testing</surname>
          </string-name>
          . - CreateSpace
          <string-name>
            <surname>Independent Publishing Platform</surname>
          </string-name>
          ,
          <year>2015</year>
          . 358 p.
        </mixed-citation>
      </ref>
      <ref id="ref19">
        <mixed-citation>
          [21]
          <string-name>
            <surname>Raphael</surname>
            <given-names>Hertzog</given-names>
          </string-name>
          , Mati Aharoni,
          <string-name>
            <surname>Jim O'Gorman. Kali Linux</surname>
          </string-name>
          <article-title>Revealed: Mastering the Penetration Testing Distribution</article-title>
          . - Offsec Press,
          <year>2017</year>
          . 314 p.
        </mixed-citation>
      </ref>
      <ref id="ref20">
        <mixed-citation>
          [22]
          <string-name>
            <surname>Scaner-VS</surname>
          </string-name>
          . Online http://scaner-vs.ru/trial/
        </mixed-citation>
      </ref>
      <ref id="ref21">
        <mixed-citation>
          [23]
          <article-title>Technical Guide to Information Security Testing and Assessment</article-title>
          . Online http://nvlpubs.nist.gov/nistpubs/Legacy/SP/nistspecialpublication800-
          <fpage>115</fpage>
          .pdf
        </mixed-citation>
      </ref>
      <ref id="ref22">
        <mixed-citation>
          [24]
          <string-name>
            <surname>Tedi</surname>
            <given-names>Heriyanto</given-names>
          </string-name>
          ,
          <string-name>
            <given-names>Lee</given-names>
            <surname>Allen</surname>
          </string-name>
          . Kali Linux - Assuring
          <string-name>
            <surname>Security by Penetration Testing</surname>
          </string-name>
          . - Packt
          <string-name>
            <surname>Publishing</surname>
          </string-name>
          ,
          <year>2014</year>
          . 454 p.
        </mixed-citation>
      </ref>
      <ref id="ref23">
        <mixed-citation>
          [25]
          <string-name>
            <given-names>Wil</given-names>
            <surname>Allsopp. Advanced Penetration</surname>
          </string-name>
          <article-title>Testing: Hacking the World's Most Secure Networks</article-title>
          . - John Wiley &amp; Sons,
          <year>2017</year>
          . 288 p..
        </mixed-citation>
      </ref>
    </ref-list>
  </back>
</article>