Penetration Testing
- In Turkish
- Sızma Testi
In short
Penetration testing is an authorized, simulated attack on a system that helps an organization find and fix security weaknesses before real attackers do.
What is penetration testing?
Penetration testing, or pen testing, is a security assessment in which trained testers try to break into an application, network, or organization the way a real attacker would, but with written permission and agreed rules. The goal is not to cause damage but to discover weaknesses, show how serious they are, and give the owners clear steps to fix them.
A test starts with scoping: the client and testers agree in writing which systems are in scope, which techniques are allowed, and when testing may happen, often called the rules of engagement. Testers then gather information, look for vulnerabilities such as SQL injection, broken access control, or misconfigured cloud storage, and carefully confirm which ones can actually be exploited. The engagement ends with a report that ranks findings by risk and explains how to fix each one, often followed by a retest to confirm the fixes work.
It is like hiring a locksmith to try every door and window of your house with your permission, then hand you a list of weak locks. Tests can be black box, where testers start with no inside knowledge, white box, where they get source code and documentation, or gray box, somewhere in between. Organizations run them before major launches, after big changes, and to meet compliance requirements.
Pen testing is often confused with vulnerability scanning. A scanner is an automated tool that checks systems against a list of known issues and can run continuously, while a penetration test is a time-boxed, mostly manual exercise where people chain weaknesses together and prove real impact. Testing any system without explicit authorization from its owner is illegal in most countries, even with good intentions, which is why signed agreements and bug bounty program rules define exactly what is allowed.
Key takeaways
- A penetration test is an authorized, simulated attack with a written scope and rules of engagement.
- The goal is to find, prove, and help fix vulnerabilities, not to cause damage.
- Black-box, gray-box, and white-box tests differ in how much the testers know upfront.
- Automated vulnerability scanning complements pen testing but doesn't replace it.
- Testing systems without the owner's permission is illegal, even with good intentions.
Example
# Rules of engagement, signed by the system owner before any testing
engagement: web-app-pentest-2026-q4
authorized_by: "Head of Security, Example Corp (signed 2026-10-01)"
window: "2026-10-06 to 2026-10-17, 09:00-18:00 UTC"
in_scope:
- https://staging.example.com
- https://api-staging.example.com
out_of_scope:
- production databases
- denial-of-service testing
- social engineering of employees
emergency_contact: security@example.comReaders ask
Is penetration testing legal?
Yes, when the system owner has given explicit written permission and the testing stays within the agreed scope. Testing systems you don't own or aren't authorized to test is illegal in most countries, even if you only intend to report what you find.
What is the difference between a penetration test and a vulnerability scan?
A vulnerability scan is an automated check for known weaknesses and can run often. A penetration test is a deeper, largely manual exercise where skilled testers confirm which weaknesses are exploitable and how they could be combined into a real attack.
How often should you run a penetration test?
Many organizations test at least once a year and after major changes, such as a new product launch or a large infrastructure migration. Continuous automated scanning and a bug bounty program can fill the gaps between tests.
See also
- SQL InjectionSecurity, p. 40SQL injection is an attack where user input is treated as part of a database query, letting an attacker read, change, or delete data they should not reach.
- XSSSecurity, p. 48XSS is a vulnerability that lets an attacker inject malicious JavaScript into a trusted website so that it runs in other users' browsers.
- AuthorizationSecurity, p. 3Authorization is the process of deciding what an authenticated user or service is allowed to do, such as which data it can read, change, or delete.
- Zero TrustSecurity, p. 49Zero trust is a security model that trusts no user, device, or network by default and verifies every request based on identity, device health, and context.
- Code ReviewVersion Control, p. 4A code review is the practice of having other developers check code changes before they are merged, to catch bugs, improve quality, and share knowledge.
- PhishingSecurity, p. 27Phishing is a social engineering attack in which criminals pose as a trusted company or person to trick people into revealing passwords, codes, or money.
Spotted a mistake or something missing on this page?Suggest an edit