Penetration Testing for Developers, Newbies and Freelancers: Securing Systems (Part 1)
17 Oct 2024 · Rabington Chitima
If you've worked in a small team or a software development house, you've likely taken on tasks that usually require multiple specialists. Whether it's something outside your job description or part of a side project or consultancy role, you've probably had to wear many hats. This guide is here to help. In the first part, we'll cover the background of securing your code, and in the second part, we'll dive into tools and techniques to make it happen.
What are we talking about? As the title suggests, penetration testing. According to Cloudflare, "Penetration testing (or pen testing) is a security exercise where a cybersecurity expert (in this case, you) attempts to find and exploit vulnerabilities in a system." The goal is to identify weak points in the system's defences before attackers can. While there are specialists in this field, the purpose of this guide is to ensure that, as a developer, you've done your part in minimizing potential risks.
This naturally raises the question: what are the potential security risks? Instead of diving deep into each one, I'll refer you to OWASP (Open Web Application Security Project), which ranks and explains the most common risks — the OWASP Top 10 Web Application Security Risks.
OWASP encourages companies and developers to adopt the document and start the process of ensuring that their web applications minimize these risks. Using the OWASP Top 10 is perhaps the most effective first step towards changing the software development culture within your organization into one that produces more secure code.
Securing APIs and Web Applications
Now that we've touched on some of the potential risks, let's explore how developers can protect themselves from these threats.
API Gateway & Firewalls
- API Gateway: Acts as a single entry point for managing and securing API traffic. Provides authentication, rate limiting, and logging to help safeguard against attacks.
- Web Application Firewall (WAF): Adds an additional layer of protection, helping to block common attacks such as SQL injection, cross-site scripting (XSS), and brute force attacks.
CORS Configuration
CORS (Cross-Origin Resource Sharing) controls how resources on a web application can be requested from another domain. Misconfigured CORS policies can expose sensitive endpoints to unauthorized access.
- Best Practices: Restrict access to trusted domains by specifying exact origins, and avoid using wildcards (
*). Implement strict headers to prevent unauthorized requests from untrusted sources.
Rate Limiting & Throttling
As a developer, you understand the expected traffic on your endpoints. However, when hackers attempt attacks, they often flood the system with more requests than anticipated. Implement rate limiting to cap the number of requests per user or IP address, mitigating the risk of denial-of-service (DoS) and brute-force attacks. Request throttling helps further by delaying or blocking excessive requests. Most hosting environments come with built-in configurations to support these protective measures.
Access Control
- Role-Based Access Control (RBAC): Clearly document user roles and permissions, then implement these roles in your system to restrict access to sensitive data and functionality appropriately.
- Principle of Least Privilege: Ensure that users and services only have access to the minimum resources necessary to perform their tasks.
Authentication & Authorisation
While I won't dive too deep into the details of your authentication methods, it's crucial to continuously refine your existing mechanisms:
- OAuth 2.0: Use OAuth 2.0 for delegated access, providing secure and controlled authorization to third-party applications.
- Multi-Factor Authentication (MFA): Add an extra layer of security, such as 2FA, to protect both your system and users.
- JWT (JSON Web Tokens): Secure your APIs with stateless JWTs that contain claims and can be verified without querying a database on each request.
Session Management
- Sessions should expire: Implement session expiration and invalidation mechanisms to protect against session hijacking.
- Secure & HttpOnly Cookies: Mark cookies as Secure (for HTTPS) and HttpOnly (inaccessible to JavaScript) to prevent cross-site scripting (XSS) and man-in-the-middle attacks.
Encryption
- HTTPS (TLS): Ensure all communication between clients and servers is encrypted to prevent eavesdropping and man-in-the-middle attacks.
- Data Encryption: Encrypt sensitive data both in transit and at rest (e.g. databases, file storage).
- Key Management: Always securely store any keys used for encryption.
Security Headers
- Content Security Policy (CSP): Mitigate XSS attacks by specifying trusted sources for loading content.
- X-Frame-Options: Protect against clickjacking by controlling whether your content can be embedded in an iframe.
- X-Content-Type-Options: Prevent browsers from MIME-sniffing and interpreting content types incorrectly.
Third-Party Libraries & Dependencies
- Regular Updates: Keep all dependencies up to date to patch known vulnerabilities. Tools like cdnjs can help track and update vulnerable versions.
- Documentation: Maintain detailed documentation of all third-party dependencies used in your project for better tracking and security audits.
Upgrades and Updates
Many high-profile security breaches occur due to vulnerabilities introduced during updates. As a developer, it's essential to maintain proper API versioning and a deprecation strategy. Ensure thorough integration testing with the unchanged parts of your system to prevent breaking the system or leaving older, less secure APIs accessible.
Monitor Deployments and Pipelines
- Always have code reviews in place — another pair of eyes can catch potential issues. Use static analysis tools for vulnerability scanning of your codebase.
- Integrate security tests into your CI/CD pipeline to catch issues early before they reach production.
Others
Additional practices to consider include audit and logging, input validation, and security awareness training. Your stakeholders, including users, are often the weakest link in security, so educating them on best practices and threats like phishing and social engineering is crucial.
Wrapping Up
Securing your system is an ongoing process, and implementing best practices requires continuous learning to keep up with evolving threats! I decided to break this guide into two parts, as it became quite lengthy. In the next part, we'll dive into security scanning and penetration testing using tools like SQLMap, Burp Suite, and Nmap — and maybe touch on Wireshark.