Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

It's a bit of both. It's not so much a checklist as a classes of bugs, but close enough. That includes vulnerabilities like SQL injection, command injection, stored and reflected XSS, et cetera. The WAHH (Web Application Hacker's Handbook) is a good place to start here; it walks through a lot of these standard classes of web app vulns.

Something WAHH touches on, and experienced pentesters get a feel for, is more complex interactions. Often that means chaining several not-so-bad bugs together to build something really exciting. Sometimes they're just obscure consequences of say, a rather complex authorization system. These are typically a lot harder to find, and may involve simultaneous code audits. Ideally, your long-term in-house security people find these, because any attacker that does is in the 95th cleverness percentile.

So, TL;DR: start with WAHH; then go find some vulns, and start thinking about what the app does in terms of alternative things a program could do that a reasonable programmer who was just trying to get it to work might not have thought about.

If you're looking for tools to play with, you can do worse than downloading Kali and running it on a VM. If nothing else, it'll give you a pretty big catalog of tools to start looking at. I think WAHH covers basic Burp Suite usage, but Kali has some other tools like sqlmap and BeEF that aren't too tricky to get started with.

WAHH: http://mdsec.net/wahh/ Kali: https://www.kali.org/



Also want to mention Web Hacking 101 [0], which is written specifically for newbies in vulnerability searching, with real cases and explanation of how certain bugs are or could be found.

[0] https://leanpub.com/web-hacking-101




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: