Hands-On Web Penetration Testing with Metasploit
上QQ阅读APP看书,第一时间看更新

Reporting

Reporting is one of the most important phases, as patching all the issues wholly depends on the details presented in your report. The report must contain three key elements:

  • The criticality of the bug
  • The steps needed to reproduce the bug
  • Patch suggestions

In summary, the pen test life cycle phases can be presented in the following way:

In the next section, we will talk about the Common Weakness Enumeration (CWE) and the two top CWEs.