Skip to Content
Practical Web Penetration Testing
book

Practical Web Penetration Testing

by Gus Khawaja
June 2018
Intermediate to advanced
294 pages
7h 5m
English
Packt Publishing
Content preview from Practical Web Penetration Testing

Information disclosure – confidentiality

Threat Description

Exposing information (at rest and in transit) to someone not authorized to see it.

Threat Target

Application (WordPress) data.

Attacker Steps

An attacker can do the following for this type of threat:

  • Read data in transit
  • Read data from logs
  • Read data from error messages
  • Blog article contents can reveal confidential information
  • A hacker can exfiltrate data through SQL Injection attacks
  • A hacker can query data if he/she has access directly to the database

Counter-measure

  • Use only TLS for data in transit
  • Logs should not contain confidential information
  • Error messages should be generic
  • Blog articles will be approved by admins before they are published
  • Admins ...
Become an O’Reilly member and get unlimited access to this title plus top books and audiobooks from O’Reilly and nearly 200 top publishers, thousands of courses curated by job role, 150+ live events each month,
and much more.
Start your free trial

You might also like

Hands-On Web Penetration Testing with Metasploit

Hands-On Web Penetration Testing with Metasploit

Harpreet Singh, Himanshu Sharma
Penetration Testing

Penetration Testing

Georgia Weidman

Publisher Resources

ISBN: 9781788624039Supplemental Content