Главная
Study mode:
on
1
Intro
2
More Specifically
3
Differences from standard testing
4
The regular methodologies
5
Find the road less traveled
6
Port Scanning!
7
Mapping tips
8
Directory Bruteforce Workflow
9
Mapping/Vuln Discovery using OSINT
10
New Project: Maps
11
Using the Maps Project: Crawling
12
New Tool: Intrique
13
Session (better be quick)
14
Other XSS Observations
15
SWF Parameter XSS
16
SQL Injection Observations
17
SQLmap All Tamper Scripts
18
Best SQL injection resources
19
Local file inclusion
20
Remote file includes and redirects
21
Malicious File Upload ++
22
Data Driven Assessment (diminishing return FTW)
23
Bug Hunters Methodology
Description:
Learn advanced web hacking techniques and methodologies in this 50-minute conference talk from HouSecCon 6 (2015). Explore the differences between standard testing and more specialized approaches, discover unconventional methods for port scanning and mapping, and delve into directory bruteforce workflows. Gain insights on vulnerability discovery using OSINT and learn about new tools like the Maps Project and Intrique. Examine various attack vectors including XSS, SQL injection, file inclusion, and malicious file uploads. Understand the concept of data-driven assessment and discover the most effective resources for SQL injection. Enhance your web hacking skills with this comprehensive overview of the Bug Hunter's Methodology.

How to Shot Web - Better Hacking in 2015

Add to list
0:00 / 0:00