Skip to Main Content
Hands-On Application Penetration Testing with Burp Suite
book

Hands-On Application Penetration Testing with Burp Suite

by Carlos A. Lozano, Dhruv Shah, Riyaz Ahemed Walikar
February 2019
Beginner to intermediate content levelBeginner to intermediate
366 pages
7h 49m
English
Packt Publishing
Content preview from Hands-On Application Penetration Testing with Burp Suite

Discovering authentication weaknesses

After services, ports, and technology detection, the next step is to navigate and understand the application's flow. Here, we will focus on the authentication section.

  1. So, open Burp Suite, and after configuring the web browser, go to https://www.mercadolibre.com.mx/.
  2. As we mentioned before, Mercado Libre is a big online retailer, which is an intermediate party between sellers and buyers offering package services and financial services.
  3. Enter valid credentials in the login section in order to understand how works.
  4. A resume about the authentication flow is given here:
    • The user enters an email address or username and a password
    • The user is logged in
    • If the user closes the session, the next time they enter ...
Become an O’Reilly member and get unlimited access to this title plus top books and audiobooks from O’Reilly and nearly 200 top publishers, thousands of courses curated by job role, 150+ live events each month,
and much more.
Start your free trial

You might also like

Burp Suite: Web Application Penetration Testing

Burp Suite: Web Application Penetration Testing

Sunil Gupta
Penetration Testing

Penetration Testing

Georgia Weidman
Penetration Testing

Penetration Testing

James Hayes, Nick Furneaux, Jims Marchang, Rob Ellis, Jason Charalambous, Moinuddin Zaki, Peter Taylor, Roderick Douglas, Felix Ryan, Ceri Charlton, Gemma Moore, Tylor Robinson, Sharif Gardner

Publisher Resources

ISBN: 9781788994064OtherErrata PagePurchase Link