Module 9 (Web Application Attacks)
Web Application Enumeration
Programming language and Frameworks
PHP - ASP.net - JSP - PYTHON - JAVA and More
Wappalyzer - inspecting URLs - whatweb - Error
Web Server Software
Apache - Nginx - IIS
Wappalyzer - whatweb - Error
Database software
MySQL - MariaDB - MongoDB - Oracle - SQL Server
Wappalyzer - Error
Server OS
Linux - Windows
Wappalyzer - NSE (Nmap Script Engine)
Web Application Assessment Tools
Fuzz Directories
Drip - gobuster - dirsearsh - fuff - wfuzz
Wfuzz
Fuzzing Dir
Fuzzing Files
.bak, .php, .zip . xml , .json ...etc
Dirbuaster
Fuzzing Parameters In URLs
Fuzzing Cookies
Fuzzing POST Requests
Test Vulnerabilities
Nikto - Nessus - acunetix - netsparker - burp and zap proxy
OWASP Top Ten
A01:2021-Broken Access Control
A02:2021-Cryptographic Failures
A03:2021-Injection
A04:2021-Insecure Design
A05:2021-Security Misconfiguration
A06:2021-Vulnerable and Outdated Components
A07:2021-Identification and Authentication Failures
A08:2021-Software and Data Integrity Failures
A09:2021-Security Logging and Monitoring Failures
A10:2021-Server-Side Request Forgery
Last updated