Chapter 6

Exploiting Application-Based Vulnerabilities

This chapter covers the following topics related to Objective 3.3 (Given a scenario, research attack vectors and perform application-based attacks.) of the CompTIA PenTest+ PT0-002 certification exam:

  • Overview of web application-based attacks for security professionals and the OWASP Top 10

  • How to build your own web application lab

  • Understanding business logic flaws

  • Understanding injection-based vulnerabilities

  • Exploiting authentication-based vulnerabilities

  • Exploiting authorization-based vulnerabilities

  • Understanding cross-site scripting (XSS) vulnerabilities

  • Understanding cross-site request forgery and server-side request forgery attacks

  • Understanding clickjacking

  • Exploiting security misconfiguration ...

Get CompTIA PenTest+ PT0-002 Cert Guide, 2nd Edition now with the O’Reilly learning platform.

O’Reilly members experience books, live events, courses curated by job role, and more from O’Reilly and nearly 200 top publishers.