February 2019
Beginner to intermediate
366 pages
7h 49m
English
There are times when the user is not able to take shells, or a situation might arise where the application might be vulnerable to blind SQL or XXE attacks; so what should be done now? Well, in this case, the attacker can still try to exfiltrate information using out-of-band techniques or simple techniques. Using these techniques, the attacker can exfiltrate a lot of information, such as extracting user credentials from the database, reading files via XXE injection, and much more. In later chapters, we will see how we can use out-of-band techniques for data exfiltration using Burp.
Read now
Unlock full access