February 2019
Beginner to intermediate
366 pages
7h 49m
English
As discussed earlier, once the application is scanned using automated scanners and manual tests, this stage is then progressed. Findings such as SQL injection file upload bypass, XXE attacks, and so on, allow an attacker/tester to gain the capability to dig further and attack the application to take shells. So, once the issues are discovered in this stage, the pentester will go ahead and exploit those issues to see the extent to which the information can be extracted. This is the phase where an attacker can chain multiple vulnerabilities to see if he can cause a bigger bug. There are many submission reports on HackerOne that show how testers have chained multiple vulnerabilities that eventually lead to remote ...
Read now
Unlock full access