131
Page views
5
Files
1
Videos
1
R.Links

Icon
Syllabus

UNIT
1
Hacking Web Apps and Profiling

Web Application Hacking: GUI web Hacking, URI Hacking, Methods Headers and Body, Resources. The Web Client and HTML, Other Protocols, How & Why Web Apps attack. Infrastructure Profiling: Foot printing and Scanning, Basic Banner Grabbing, Advanced HTTP Fingerprinting, Infrastructure Intermediaries. Application Profiling: Manual Inspection, Search Tools for Profiling, Automated Web Crawling, General Countermeasures.

UNIT
2
Bypassing and Attacking Web Authentication

Web Authentication Threats: Username/password Threats, Password Guessing and its Countermeasures, Eavesdropping attacks and its Countermeasures, Forms-based Authentication attacks and its countermeasures. Stronger web Authentication, Web Authentication Services. Bypassing Authentication: Token Replay, Cross-site Request Forgery, Identity Management.

UNIT
3
Penetration Testing and Input Injection Attacks

Where to find Attack vectors, Common Input Injection Attacks: Buffer Overflow, Canonicalization and its countermeasures, Advanced Directory Traversal, Navigating Without Directory Listing, HTML Injection: XSS, Embedded scripts, Cookies and Predefined Headers, Counter countermeasures. SQL Injection: SUB Queries, UNION, SQL Injection countermeasures, XPATH Injection and its countermeasures, LDAP Injection.

UNIT
4
Metasploit

Introduction, Metasploit Basics: Terminology, Metasploit Interfaces, Metasploit Utilities. Intelligence Gathering: Passive Information Gathering, Active Information Gathering, Target Scanning. Vulnerability Scanning: Basic Vulnerability Scan, Scanning with scanning tools, Using Scan Results for Autopwning.

UNIT
5
Attacking Users

Defacing Content, Capturing User Input: Using Focus Event, Using Keyboard Events, Using Mouse and Pointer Events, Using Form Events, Social Engineering: Using TabNabbing, Abusing UI Expectations: Using Fake Login Prompts, Pretty Theft, Gmail Phishing.

Reference Book:

1 )The Browser Hacker’s Handbook by Wade Alcorn, Christian Frichot and Michele Orru – Wiley Publication 2 )Web Penetration Testing with Kali Linux by Joseph Muniz, Aamir Lakhan – Packt Publication

Text Book:

1 ) Hacking Exposed Web Application, 3rd Edition by Joel Scambray, Vincent Liu, Caleb Sima 2 )The Web Application Hacker's Handbook: Finding and Exploiting Security Flaws by Dafydd Stuttard and Marcus Pinto Wiley Publication 3 )Metasploit - The Penetration Tester's Guide by David Kennedy , Jim O'gorman , Devon Kearns and Mati Aharoni – No Starch Press Publication

 

Print    Download