𝔖 Scriptorium
✦   LIBER   ✦

πŸ“

Attacking and Exploiting Modern Web Applications: Discover the mindset, techniques, and tools to perform modern web attacks and exploitation

✍ Scribed by Simone Onofri, Donato Onofri


Publisher
Packt Publishing
Year
2023
Tongue
English
Leaves
338
Category
Library

⬇  Acquire This Volume

No coin nor oath required. For personal study only.

✦ Synopsis


Master the art of web exploitation and bug bounty hunting with real CVEs and CTFs on SAML, WordPress, IoT, ElectronJS, and Ethereum Smart Contracts.

Purchase of the print or Kindle book includes a free PDF eBook.
Β 
Key Features

  • Learn to discover vulnerabilities using source code, dynamic analysis, and decompiling binaries.
  • Find and exploit vulnerabilities like SQL Injection, XSS, Command Injection, RCE, and Reentrancy.
  • Analyze real security incidents based on MITRE ATT&CK to understand the risk at the CISO level.Β 
Book Description
Web Attacks and Exploits pose an ongoing threat to the interconnected world. This comprehensive book explores the new challenges of web application security, providing an in-depth understanding of hackers' methods. It equips readers with the practical knowledge and skills needed to effectively understand these attacks, accompanying them through 3 CTFs and explaining the discovery of 7 CVEs.
The book starts by emphasizing the importance of mindset and toolset in conducting successful attacks. It helps you understand the required methodologies and frameworks, how to configure the environment using interception proxies and automate tasks with Bash and Python, and how to set up a research lab.
The book explores how to attack the authentication layer focusing on SAML, internet-facing web applications (specifically WordPress and SQL injection), exploiting vulnerabilities in IoT devices such as Command Injection. It also covers attacks on Electron JavaScript-based applications (XSS and RCE) and the security challenges of auditing and exploiting Ethereum Smart Contracts written in Solidity. The book concludes by describing how to disclose vulnerabilities. Each chapter analyses confirmed cases of exploitation mapped with MITRE ATT&CK.
By the end of this book, you will enhance your ability to find and exploit web vulnerabilities.
Β 
What you will learn
  • Understand the mindset, methodologies, and toolset for Web Attacks and Exploitation.
  • Learn how SAML and SSO work and find their vulnerabilities
  • Understand WordPress and how to exploit SQL Injections
  • Learn how IoT Devices work and to exploit Command Injection
  • Understand ElectronJS Applications and transform an XSS to an RCE
  • Learn how to audit Solidity's Ethereum Smart Contracts
  • Understand how to decompile, debug, and instrument Web Applications
Who this book is for
We aim the audience at anyone who must ensure their organization's security. Penetration Testers and Red Teamers who want to deepen their knowledge of the current security challenges for web applications; Developers and DevOps EngineersΒ who want to get into the mindset of an attacker; and Security Managers and CISOs to truly understand the impact and the Risk of Web, IoT, and Smart Contracts. Basic knowledge of Web Technologies and related protocols is a must.
Β 
Table of Contents
  1. Mindset and Methodologies
  2. Toolset
  3. Attacking the Authentication Layer: a SAML use case
  4. Attacking Internet-Facing Web Applications: SQL Injection and Cross-Site Scripting (XSS) on WordPress
  5. Attacking IoT Devices: Command Injection and Path Traversal
  6. Attacking Electron JavaScript Applications: from Cross-Site Scripting (XSS) to Remote Command Execution (RCE)
  7. Attacking Ethereum Smart Contracts: Reentrancy, Weak Sources of Randomness and Business Logic
  8. Continuing the Journey of Vulnerability Discovery


πŸ“œ SIMILAR VOLUMES


Attacking and Exploiting Modern Web Appl
✍ Simone Onofri, Donato Onofri πŸ“‚ Library πŸ“… 2023 πŸ› Packt Publishing 🌐 English

<span>Master the art of web exploitation and bug bounty hunting with real CVEs and CTFs on SAML, WordPress, IoT, ElectronJS, and Ethereum Smart Contracts.</span><span><br><br></span><span>Purchase of the print or Kindle book includes a free PDF eBook.</span><span><br>Β <br></span><span>Key Features</

Attacking and Exploiting Modern Web Appl
✍ Simone Onofri, Donato Onofri πŸ“‚ Library πŸ“… 2023 πŸ› Packt Publishing 🌐 English

<span>Master the art of web exploitation and bug bounty hunting with real CVEs and CTFs on SAML, WordPress, IoT, ElectronJS, and Ethereum Smart Contracts.</span><span><br><br></span><span>Purchase of the print or Kindle book includes a free PDF eBook.</span><span><br>Β <br></span><span>Key Features</

Attacking and Exploiting Modern Web Appl
✍ Simone Onofri, Donato Onofri πŸ“‚ Library πŸ“… 2023 πŸ› Packt Publishing 🌐 English

A comprehensive guide to effectively understand web attacks for web application security, featuring real-world bug bounty hunting techniques, CVEs, and CTFs Purchase of the print or Kindle book includes a free PDF eBook Key Features: Learn how to find vulnerabilities using source code, dynamic analy

Attacking and Exploiting Modern Web Appl
✍ Simone Onofri, Donato Onofri πŸ“‚ Library πŸ“… 2023 πŸ› Packt Publishing 🌐 English

A comprehensive guide to effectively understand web attacks for web application security, featuring real-world bug bounty hunting techniques, CVEs, and CTFs Purchase of the print or Kindle book includes a free PDF eBook Key Features: Learn how to find vulnerabilities using source code, dynamic analy

The Basics of Web Hacking: Tools and Tec
✍ Josh Pauli πŸ“‚ Library πŸ“… 2013 πŸ› Syngress 🌐 English

<p><i>The Basics of Web Hacking</i> introduces you to a tool-driven process to identify the most widespread vulnerabilities in Web applications. No prior experience is needed. Web apps are a "path of least resistance" that can be exploited to cause the most damage to a system, with the lowest hurdle