Главная
Study mode:
on
1
Introduction
2
Agenda
3
Why use source code
4
Hybrid Analysis Mapping
5
Initial Goal
6
Dynamic Application Security Testing
7
Static Application Security Testing
8
Vulnerability Taxonomy
9
Static and Dynamic Locations
10
Endpoint Database
11
Dynamic Results
12
Plugin Overview
13
Plugin Installation
14
Attack Surface Enumeration
15
False Positives
16
Example
17
Supported Technologies
18
Android Applications
19
Debug Parameters
20
MVC Model Configuration
21
MVC Example
22
Questions
23
Data Flow Analysis
Description:
Explore the fundamentals of source-assisted web application penetration testing in this 45-minute conference talk from AppSecEU 2016 in Rome. Learn why utilizing source code is crucial, understand the concept of Hybrid Analysis Mapping, and discover the differences between Dynamic and Static Application Security Testing. Delve into vulnerability taxonomy, static and dynamic locations, and endpoint databases. Gain insights into plugin installation, attack surface enumeration, and handling false positives. Examine practical examples, including Android applications, debug parameters, and MVC configurations. Conclude with an overview of data flow analysis to enhance your web application security testing skills.

The ABCs of Source-Assisted Web Application Penetration Testing

OWASP Foundation
Add to list
0:00 / 0:00