Hands-On Application Penetration Testing with Burp Suite
by Carlos A. Lozano, Dhruv Shah, Riyaz Ahemed Walikar
Summary
In this chapter, we learned the normal tools that Burp Suite uses to exploit different types of vulnerabilities. In particular, we exploited SSRF and XSPA to execute commands, extract information and perform tasks in the internal networks. Also, we reviewed the origin of these vulnerabilities. We reviewed an IDOR vulnerability, learned how to exploit it manually, and how to automate its exploitation using Intruder. Next, we reviewed some vulnerabilities related to configurations; how they could be critical and not critical, and how we can automate some of them.
We also performed brute forcing to look for valid credentials in two different types of authentications. We created a malicious PDF and learned how to upload it to a website ...
Become an O’Reilly member and get unlimited access to this title plus top books and audiobooks from O’Reilly and nearly 200 top publishers, thousands of courses curated by job role, 150+ live events each month,
and much more.
Read now
Unlock full access