← All walkthroughs

External web app to an internal foothold

A classic external penetration test: from internet-facing recon, through a web-application flaw, to a web shell and a pivot into the internal network.

External → internal network Beginner WebExternalPivoting
Authorized testing only. This is a conceptual, defensive-aware walkthrough that maps an attack path to MITRE ATT&CK, detection and mitigation, and links to references for the detail. It is not a copy-paste playbook. Use it only against systems you own or are explicitly permitted to test.

Scenario

You have a signed scope covering a company's public web application and its external IP range. The goal is to demonstrate whether an internet-based attacker can reach the internal network. Nothing is assumed — you start with only the in-scope domain.

Practice this path: OWASP WSTG · MITRE ATT&CK
  1. 1

    Reconnaissance

    Map the external attack surface

    Enumerate subdomains, resolve hosts, fingerprint the web stack and run a focused service scan over the in-scope range. Catalogue every app, login page, API and exposed admin panel, and note software versions for later.

    Detection

    Bursts of DNS lookups, port scans and 404/robots probing from a single source show up in WAF and perimeter IDS logs and in web-server access logs.

    Mitigation

    Reduce external surface: retire stale subdomains, hide version banners, rate-limit and geo/WAF-filter noisy scanning, and keep an accurate asset inventory.

  2. 2

    Initial Access

    Exploit a public-facing application flaw

    Probe the highest-value inputs for the common server-side classes — injection, unrestricted file upload, SSRF, deserialization. Confirm a single reliable, in-scope vulnerability rather than chaining risky payloads blindly.

    Detection

    WAF signatures, spikes of 500 errors, and anomalous query patterns in application logs; file-integrity monitoring on web roots flags newly written files.

    Mitigation

    Validate and parameterize all input, constrain uploads by type/with out-of-webroot storage, patch frameworks, and run a WAF in blocking mode.

  3. 3

    Execution / Persistence

    Gain command execution via a web shell

    Where the flaw allows it, place a minimal authenticated web shell to turn the web vulnerability into interactive command execution on the server, documenting exactly what was dropped and where for clean-up.

    Detection

    New or modified files in the web root, web-server processes spawning shells, and outbound connections from the web tier are strong signals in EDR and web-server logs.

    Mitigation

    Read-only/immutable web roots, least-privilege service accounts, egress filtering from the web tier, and alerting on web-server child processes.

  4. 4

    Discovery

    Understand the host and find reachable internal systems

    From the foothold, enumerate the local host, configuration files and environment, and discover which internal services and segments are reachable from this DMZ host.

    Detection

    Internal scanning from a DMZ host, reads of sensitive config files, and unusual east-west connections appear in NetFlow and host telemetry.

    Mitigation

    Segment the DMZ from internal networks, store secrets in a vault (not config files), and monitor for internal scanning originating in the DMZ.

    References linuxprivilegeesc · nmap
  5. 5

    Lateral Movement (Pivot)

    Tunnel into the internal network

    Set up a controlled proxy/tunnel through the foothold so in-scope internal systems can be reached for the next phase, keeping all traffic within the authorized scope.

    Detection

    Long-lived encrypted tunnels, proxy software on a web server, and traffic to internal hosts that the DMZ host never normally contacts.

    Mitigation

    Strict egress and east-west firewall rules, allow-listed outbound destinations, and detection of tunneling/proxy binaries on servers.

Key takeaways

  • One exploitable web flaw plus a flat network is enough to turn an external test into an internal compromise.
  • Segmentation and egress control between the DMZ and internal network are what break this chain.
  • Every offensive step leaves telemetry — recon, file writes, tunnels — so defenders have multiple catch points.