Hands-On Application Penetration Testing with Burp Suite
by Carlos A. Lozano, Dhruv Shah, Riyaz Ahemed Walikar
Summary
In this final chapter, we reviewed other scenarios that can be used to assess an application. In this chapter, we looked for SQL injections and exploited one of them using different methods.
For an application security assessment, I recommend avoiding the manual exploitation methods, because we will have less time to use them. They are useful when it is not possible to find vulnerabilities using other methods.
In this chapter, you learned how to analyze the parameter behavior in a request to infer what could be vulnerable and reduce the time analysis. Later, we looked into detecting Blind SQL injection vulnerabilities using Burp Suite's scanner, SQLMap, and the Intruder tool. Finally, we learned how to guess a tracking number using ...
Become an O’Reilly member and get unlimited access to this title plus top books and audiobooks from O’Reilly and nearly 200 top publishers, thousands of courses curated by job role, 150+ live events each month,
and much more.
Read now
Unlock full access