Tasks
Footprint the Web Infrastructure
Perform Web Application Reconnaissance using Nmap and Telnet
nmap -T4 -A -v <Target Web Application>telnet www.moviescope.com 80
GET / HTTP/1.0Perform Web Application Reconnaissance using WhatWeb
Perform Web Spidering using OWASP ZAP
Detect Load Balancers
Identify Web Server Directories
Perform Web Application Vulnerability Scanning using Vega
Identify Clickjacking Vulnerability
Perform Web Application Attacks
Perform Brute-force Attack using Burp Suite
Perform Parameter Temparing using Burp Suite
Identify XSS Vulnerability using PwnXSS
Exploit Parameter Tampering and XSS Vulnerabilities in Web Applications
Perform CSRF Attack
Enumerate and Hack a Web Application using WPScan and Metasploit
Exploit RCE Vulnerability
Command Injection Page (Low Mode)
Exploit File Upload Vulnerability
Create PHP Payload
Create a Listener
Exploit Log4j Vulnerability
Extract and Setup Jdk
Update the JDK Path in the Poc.py file
Create a Netcat Listener
Create a Payload
In the Netcat window
Detect Web Application Vulnerabilities
N-Stalker Web Application Security Scanner
Last updated