Mastering Kali Linux for Web Penetration Testing by Michael McPhee
Author:Michael McPhee [McPhee, Michael]
Language: eng
Format: azw3, mobi, epub, pdf
Tags: COM053000 - COMPUTERS / Security / General, COM060080 - COMPUTERS / Web / General, COM060040 - COMPUTERS / Security / Online Safety & Privacy
Publisher: Packt Publishing
Published: 2017-06-28T04:00:00+00:00
Sample phishing lure, used to test employees. Every link in here is potentially tainted.
Hyperlinks, graphics, anything interactive in the page or the e-mail can be a useful lure, and when attacking a specific person or team, your efforts on social media will have a huge impact on your success rate here.
Let's go Metasploiting
A lot of the tools we've used in this book so far are focused on web applications and have proven quite handy in assessing the vulnerabilities that may exist in a website. One of the more general tools in use across all pen testing domains, Metasploit (https://www.metasploit.com), actually offers some great value in testing against many of the top web app vulns, XSS included. Metasploit likely needs no introduction; chances are you are using it as a significant part of your workflow or methodology. That being said, it is a framework that incorporates a wide variety of extensible recon and scanning modules to populate a database of hosts and corresponding vulns. This database allows Metasploit to then pivot into the exploitation phase, where exploits can be launched actively or in some cases are bundled into a payload for file-based delivery. The community surrounding Metasploit is very active, and literally hundreds of plugins and modules have been crafted to make Metasploit everyone's favorite foundational pen test tool.
Download
Mastering Kali Linux for Web Penetration Testing by Michael McPhee.mobi
Mastering Kali Linux for Web Penetration Testing by Michael McPhee.epub
Mastering Kali Linux for Web Penetration Testing by Michael McPhee.pdf
This site does not store any files on its server. We only index and link to content provided by other sites. Please contact the content providers to delete copyright contents if any and email us, we'll remove relevant links or contents immediately.
Effective Threat Investigation for SOC Analysts by Yahia Mostafa;(6578)
Practical Memory Forensics by Svetlana Ostrovskaya & Oleg Skulkin(6298)
Machine Learning Security Principles by John Paul Mueller(6271)
Attacking and Exploiting Modern Web Applications by Simone Onofri & Donato Onofri(5944)
Operationalizing Threat Intelligence by Kyle Wilhoit & Joseph Opacki(5905)
Solidity Programming Essentials by Ritesh Modi(4042)
Microsoft 365 Security, Compliance, and Identity Administration by Peter Rising(3681)
Operationalizing Threat Intelligence by Joseph Opacki Kyle Wilhoit(3411)
Future Crimes by Marc Goodman(3351)
Mastering Python for Networking and Security by José Manuel Ortega(3348)
Mastering Azure Security by Mustafa Toroman and Tom Janetscheck(3337)
Blockchain Basics by Daniel Drescher(3305)
Learn Computer Forensics - Second Edition by William Oettinger(3172)
Incident Response with Threat Intelligence by Roberto MartÃnez(2898)
Mobile App Reverse Engineering by Abhinav Mishra(2886)
Mastering Bitcoin: Programming the Open Blockchain by Andreas M. Antonopoulos(2873)
The Code Book by Simon Singh(2832)
From CIA to APT: An Introduction to Cyber Security by Edward G. Amoroso & Matthew E. Amoroso(2783)
Building a Next-Gen SOC with IBM QRadar: Accelerate your security operations and detect cyber threats effectively by Ashish M Kothekar(2760)
