Performing an internal port scan to the backend

A port scan is one of the most basic and useful activities of network discovery when you are assessing a network. In applications, security assessment is limited to the scope determined in the assessment, but SSRF and XSPA allow users to perform port scanning from the application. To demonstrate how you can perform this technique, we will use a vulnerable test application, created by Acunetix, which you can find at http://testphp.vulnweb.com/.

This is a vulnerable application that you can use to learn some attacks and test scripts or tools, as shown in the following screenshot:

  1. Open Burp Suite's ...

Get Hands-On Application Penetration Testing with Burp Suite now with the O’Reilly learning platform.

O’Reilly members experience books, live events, courses curated by job role, and more from O’Reilly and nearly 200 top publishers.