Threat Modeling
Having identified port 80 as open, we could enumerate any available additional systems, but we’re interested only in the single target. Let’s move on to threat modeling and attempt to identify the best route into this system.
The web page we found gives us a chance to enter input in User and Password fields. At this point, you, as a penetration tester, should think outside the box and try to determine what the best avenue is going to be. When you’re performing application security penetration tests, consider using tools other than Metasploit, such as the Burp Suite (http://www.portswigger.net/) when appropriate; don’t feel locked into a single tool set. In the following example, we’ll attempt a manual attack by entering 'TEST (notice ...
Become an O’Reilly member and get unlimited access to this title plus top books and audiobooks from O’Reilly and nearly 200 top publishers, thousands of courses curated by job role, 150+ live events each month,
and much more.
Read now
Unlock full access