Attackers generally use buffer overflows to corrupt the execution stack of a web application. By sending
carefully crafted input to a web application, an attacker can cause the
web application to execute arbitrary code, possibly taking over the
machine. Attackers have managed to identify buffer overflows in a
staggering array of products and components. Buffer overflow flaws can be present in both the web server and
application server products that serve the static and dynamic portions
of a site, or in the web application itself. Buffer overflows found in
commonly-used server products are likely to become widely known and can
pose a significant risk to users of these products. When web
applications use libraries, such as a graphics library to generate
images or a communications library to send e-mail, they open themselves
to potential buffer overflow attacks.
Everything about threat intelligence, blue team, red team, pentesting, security audit, security review, testing and assessment.
Showing posts with label web app vulnerability. Show all posts
Showing posts with label web app vulnerability. Show all posts
Friday, April 4, 2014
Friday, February 21, 2014
Web App Pentest - Part 5 XSS
In my previous article we have seen which are the different ways of
fuzzing including suffix and prefix. We used those fuzzing techniques in order
to find error messages in web application. Now as we know how to fuzz, we will
use that skill to find XSS generally known as cross site scripting.
Testing For
XSS
Without wasting much time, let us go to, Document viewer page under A3
Cross site scripting(XSS) module. In there are various method of exploiting XSS
but first we will choose simple method which is HTTP attribute.
Thursday, February 13, 2014
Monday, February 3, 2014
Web App Pentest - Part 3 Fuzzing
When We test the web application,
we do not test a single page but we test lot of page of a single web
application. So each page may have more than one variable so technically you
will be engaging with ton of variables within your web application test. So
when you inject anything to the input it is good to know what kind of effect
your injection is making to the server. In this part of these article series we
will look at the importance of simple alphabetic injection along with the web
page encoding technology and how it does effect on our testing and result.
Web App Pentest - Part 2 Indentifying Injection Points
If your web page is static, you cannot
test it as far as security concern. You can test it at some sort of view but
you can’t play with it much as compare to dynamic page. Nikto scanner is a good
utility which works best in testing static sites. There has to be some
interaction between client and server via login panel, comment section, register
page, contact us form and so on.
Saturday, January 18, 2014
Web App Pentest - Part 1 Introduction
In this series of articles, I am going to demonstrate how you
can manually exploit the vulnerability of a web application, compared to
using any automation tool, in order to find vulnerabilities in the
application. Almost all companies worldwide focus on manual testing of
web application rather than running web application scanners, which
limit your knowledge and skills and the scope of finding a vulnerability
with your testing.
For the whole series I am going to use these programs:
Tuesday, June 25, 2013
Owning OS by XSS vulnerability
In this demonstration , I am going to show you that from even a very common XSS attach, how a we can gain access to whole system. For these I am using 2 Operating system one is Kali Linux and another is XP machine which will work as a client. For exploitation I will be using Metasploit Framework(console). For particular this exploitation there is one exploit named "ms10_046_shortcut_icon_dlllloader". Basically it is able to start the local server. That server will be serving the exploits to the victim. Once victim opens that URL, he will be hacked.
Subscribe to:
Posts (Atom)




