Chapter 4. Web Server and Web Application Testing

Solutions in this chapter:

Objectives

This chapter covers port 80. A responsive port 80 (or 443) raises several questions for attackers and penetration testers:

  • Can I compromise the Web server due to vulnerabilities on the server daemon itself?

  • Can I compromise the Web server due to its unhardened state?

  • Can I compromise the application running on the Web server due to vulnerabilities within the application?

  • Can I compromise the Web server due to vulnerabilities within the application?

Introduction

This chapter explains how a penetration tester would most likely answer each of the preceding questions.

Attacking or assessing ...

Get Penetration Tester's Open Source Toolkit, 2nd Edition now with the O’Reilly learning platform.

O’Reilly members experience books, live events, courses curated by job role, and more from O’Reilly and nearly 200 top publishers.