Book Image

Building Virtual Pentesting Labs for Advanced Penetration Testing

By : Kevin Cardwell
Book Image

Building Virtual Pentesting Labs for Advanced Penetration Testing

By: Kevin Cardwell

Overview of this book

Table of Contents (20 chapters)
Building Virtual Pentesting Labs for Advanced Penetration Testing
Credits
About the Author
About the Reviewers
www.PacktPub.com
Preface
Index

Chapter 9. Assessment of Web Servers and Web Applications

In this chapter, you will learn the techniques of assessing the web servers and web applications that are a part of the vast majority of the environments we may encounter. We will discuss the following topics:

  • Analyzing the OWASP Top Ten attacks

  • Identifying web application firewalls

  • Penetrating web application firewalls

  • Tools

This chapter will provide us with information on one of the most popular attack vectors and the attack vector that is virtually accessible on any environment. Virtually all organizations will require some form of online presence. Therefore, it is a good bet we will have a web server and probably some web applications that we can use to attempt to compromise a client system and/or network.