Hands-On Application Penetration Testing with Burp Suite
by Carlos A. Lozano, Dhruv Shah, Riyaz Ahemed Walikar
Automated testing
Automated scanning is a phase carried out on a network and also on the web. Automated scanners help find out multiple flaws ranging from input validation bypass right up to SQL injection. Automated scanning is required to expedite multiple findings in a speedy manner. In automated scanning, the scanner fuzzes all the input parameters to find vulnerabilities that range in the OWASP Top 10, especially the outdated plugins and versions. It helps find sensitive files such as admin logins, as per the dictionary available with them. You should note that the application pentest should not be concluded on the basis of the automated scanning practice. Manual intervention should always be done to validate the findings. Many a time ...
Become an O’Reilly member and get unlimited access to this title plus top books and audiobooks from O’Reilly and nearly 200 top publishers, thousands of courses curated by job role, 150+ live events each month,
and much more.
Read now
Unlock full access