Skip to Main Content
Hands-On Application Penetration Testing with Burp Suite
book

Hands-On Application Penetration Testing with Burp Suite

by Carlos A. Lozano, Dhruv Shah, Riyaz Ahemed Walikar
February 2019
Beginner to intermediate content levelBeginner to intermediate
366 pages
7h 49m
English
Packt Publishing
Content preview from Hands-On Application Penetration Testing with Burp Suite

Testing for authentication page for SQL injection

In this module, we will see how to perform tests to verify if the application's authentication page is vulnerable to SQL injeciton. We will first understand how SQL injection affects the login page, what is the background logic to it, and how it executes and allows us to log in. Then we will test a few applications and see if the application is vulnerable to SQL injection or not.

The magic strings to test for SQL injection on the login page have the same logic but are represented differently due to validations. The whole aim is to try to come out of the input field of the SQL syntax and try to execute the payload as a part of the SQL query, which will result to true. For example, a few samples ...

Become an O’Reilly member and get unlimited access to this title plus top books and audiobooks from O’Reilly and nearly 200 top publishers, thousands of courses curated by job role, 150+ live events each month,
and much more.
Start your free trial

You might also like

Burp Suite: Web Application Penetration Testing

Burp Suite: Web Application Penetration Testing

Sunil Gupta
Penetration Testing

Penetration Testing

James Hayes, Nick Furneaux, Jims Marchang, Rob Ellis, Jason Charalambous, Moinuddin Zaki, Peter Taylor, Roderick Douglas, Felix Ryan, Ceri Charlton, Gemma Moore, Tylor Robinson, Sharif Gardner
Penetration Testing

Penetration Testing

Georgia Weidman

Publisher Resources

ISBN: 9781788994064OtherErrata PagePurchase Link