Hands-On Bug Hunting for Penetration Testers: A practical guide to help ethical hackers discover web application security flaws
- Forfatter
- Forlag
- Sprog
- Engelsk
- Format
- Kategori
Fakta
Detailed walkthroughs of how to discover, test, and document common web application vulnerabilities.
Key Features
• Learn how to test for common bugs
•
• Discover tools and methods for hacking ethically
•
• Practice working through pentesting engagements step-by-step
•
Book Description
Bug bounties have quickly become a critical part of the security economy. This book shows you how technical professionals with an interest in security can begin productively—and profitably—participating in bug bounty programs.
You will learn about SQli, NoSQLi, XSS, XXE, and other forms of code injection. You'll see how to create CSRF PoC HTML snippets, how to discover hidden content (and what to do with it once it's found), and how to create the tools for automated pentesting workflows.
Then, you'll format all of this information within the context of a bug report that will have the greatest chance of earning you cash.
With detailed walkthroughs that cover discovering, testing, and reporting vulnerabilities, this book is ideal for aspiring security professionals. You should come away from this work with the skills you need to not only find the bugs you're looking for, but also the best bug bounty programs to participate in, and how to grow your skills moving forward in freelance security research.
What you will learn
• Choose what bug bounty programs to engage in
•
• Understand how to minimize your legal liability and hunt for bugs ethically
•
• See how to take notes that will make compiling your submission report easier
•
• Know how to take an XSS vulnerability from discovery to verification, and report submission
•
• Automate CSRF PoC generation with Python
•
• Leverage Burp Suite for CSRF detection
•
• Use WP Scan and other tools to find vulnerabilities in WordPress, Django, and Ruby on Rails applications
•
• Write your report in a way that will earn you the maximum amount of money
Who this book is for
This book is written for developers, hobbyists, pentesters, and anyone with an interest (and a little experience) in web application security.
© 2018 Packt Publishing (E-bog): 9781789349894
Udgivelsesdato
E-bog: 12. september 2018
Andre kan også lide...
- Lifetime: The Amazing Numbers in Animal Lives Lola M. Schaefer
- Virgin: Poems Analicia Sotelo
- After the Map: Cartography, Navigation, and the Transformation of Territory in the Twentieth Century William Rankin
- Robots in Space: The Secret Lives of Our Planetary Explorers Dr Ezzy Pearson
- Flatland: A Romance of Many Dimensions Edwin Abbott
- Hollywood's War with Poland, 1939–1945 M.B.B. Biskupski
- The Concise Dictionary of Christian Theology (Revised Edition) Millard J. Erickson
- 1974: Scenes from a Year of Crisis Nick Rennison
- Bird Planet: A Photographic Journey Tim Laman
- Wayfinding: The Science and Mystery of How Humans Navigate the World M. R. O'Connor
Vælg dit abonnement
Over 1 million titler
Download og nyd titler offline
Eksklusive titler + Mofibo Originals
Børnevenligt miljø (Kids Mode)
Det er nemt at opsige når som helst
Premium
For dig som lytter og læser ofte.
129 kr. /måned
1 konto
100 timer/måned
Eksklusivt indhold hver uge
Fri lytning til podcasts
Ingen binding
Unlimited
For dig som lytter og læser ubegrænset.
159 kr. /måned
1 konto
Ubegrænset timer
Eksklusivt indhold hver uge
Fri lytning til podcasts
Ingen binding
Family
For dig som ønsker at dele historier med familien.
Fra 179 kr. /måned
2-6 konti
100 timer/måned pr. konto
Fri lytning til podcasts
Kun 39 kr. pr. ekstra konto
Ingen binding
Dig + 1 familiemedlem
2 konti179 kr. /måned
Flex
For dig som vil prøve Mofibo.
89 kr. /måned
1 konto
20 timer/måned
Gem op til 100 ubrugte timer
Eksklusivt indhold hver uge
Fri lytning til podcasts
Ingen binding
Har du en rabatkode?
Indtast koden her