The type and scope of the penetration
test will determine the need for being stealthy during a penetration test. The
reasons to avoid detection while testing are:·One of the benefits would include testing the equipment that is
supposedly protecting the network. Another could be that your client would like to know just how long
it would take the Information Technology team to respond to a targeted attack
on the environment. You will also need to understand the automated methods of
detection such as web applications, network, and host-based intrusion detection
systems that are in place to avoid triggering alerts.
Everything about threat intelligence, blue team, red team, pentesting, security audit, security review, testing and assessment.
Showing posts with label penetration testing. Show all posts
Showing posts with label penetration testing. Show all posts
Saturday, May 17, 2014
Friday, February 21, 2014
Web App Pentest - Part 5 XSS
In my previous article we have seen which are the different ways of
fuzzing including suffix and prefix. We used those fuzzing techniques in order
to find error messages in web application. Now as we know how to fuzz, we will
use that skill to find XSS generally known as cross site scripting.
Testing For
XSS
Without wasting much time, let us go to, Document viewer page under A3
Cross site scripting(XSS) module. In there are various method of exploiting XSS
but first we will choose simple method which is HTTP attribute.
Thursday, February 13, 2014
Monday, February 3, 2014
Web App Pentest - Part 3 Fuzzing
When We test the web application,
we do not test a single page but we test lot of page of a single web
application. So each page may have more than one variable so technically you
will be engaging with ton of variables within your web application test. So
when you inject anything to the input it is good to know what kind of effect
your injection is making to the server. In this part of these article series we
will look at the importance of simple alphabetic injection along with the web
page encoding technology and how it does effect on our testing and result.
Web App Pentest - Part 2 Indentifying Injection Points
If your web page is static, you cannot
test it as far as security concern. You can test it at some sort of view but
you can’t play with it much as compare to dynamic page. Nikto scanner is a good
utility which works best in testing static sites. There has to be some
interaction between client and server via login panel, comment section, register
page, contact us form and so on.
Saturday, January 18, 2014
Web App Pentest - Part 1 Introduction
In this series of articles, I am going to demonstrate how you
can manually exploit the vulnerability of a web application, compared to
using any automation tool, in order to find vulnerabilities in the
application. Almost all companies worldwide focus on manual testing of
web application rather than running web application scanners, which
limit your knowledge and skills and the scope of finding a vulnerability
with your testing.
For the whole series I am going to use these programs:
Wednesday, August 28, 2013
Information Gathering - Why? How? & What?
Lets suppose any thriller stealing movie. Think what does robbers do before they hack the bank or anything else? They gather the information. They collect each and every information about bank system, alarm methodology, CCTV interface, Guards changing time, list of weapons having with guards.After gathering information they make plan and attack or rob the bank. You all are clever. So assume they don't have these much of information and they are going to rob bank directly, what will happen ? You will find them caught with by police.
Same scenario also applied in information security world. Before attacking or testing something a hacker/tester needs to find the information about his/her target. Now this target can be a network, web application, organization or a person. In our world finding information is also called as footprinting or doxing. Also the term reconnaissance can be used sometimes.
Wednesday, July 31, 2013
Wednesday, July 24, 2013
Penetration Testing - SAMBA SERVER
Aim: The aim is to understand how the countermeasures are applied in order to protect the potential vulnerable organization using the samba server.
Detail summery of configuration in Victim computer.
The attacker system, victim server (Linux) and client (Windows XP) was setup in a virtual environment using VMware workstation 9. They all belong to the host only network and are isolated from the rest of the network.
Tuesday, July 16, 2013
Web Service With CGI Support - Penetration Testing
This report shows an hands-on penetration testing using Apache server with cgi access, it identifies some vulnerabilities and performs exploits with this vulnerability and It further patches it by mitigating this known threats.
INTRODUCTION
APACHE
APACHE
Apache can also be referred to as Apache HTTP Server. It is a standard that is established for allocating services for website online which has developed the World Wide Web. It is a free platform of web server which is been used by most of the website. The server is been used by most of the operating systems e.g. Unix, Linux, Window, Microsoft Windows, Mac OS etc but was originally designed for Unix.
Saturday, July 6, 2013
REMOTE SHELL - Penetration Testing
Introduction: SSH secure shell is used
to establish a remote connection to a Linux box where SSH service is running.
SSH runs on port 22 and applications like Open SSH v2.0 provide SSH
utilities. SSH can protect a network
from attacks like IP spoofing, IP source routing etc,. However, we will study
some vulnerabilities associated with SSH and provide necessary counter
measures.
Labels:
bruteforce,
penetration testing,
remote shell
Subscribe to:
Posts (Atom)




