Book Image

Building Virtual Pentesting Labs for Advanced Penetration Testing

By : Kevin Cardwell
Book Image

Building Virtual Pentesting Labs for Advanced Penetration Testing

By: Kevin Cardwell

Overview of this book

Table of Contents (20 chapters)
Building Virtual Pentesting Labs for Advanced Penetration Testing
Credits
About the Author
About the Reviewers
www.PacktPub.com
Preface
Index

Penetrating web application firewalls


As we have discussed previously, it can be a challenge to evade detection, and this is on these same lines as it will depend on how the administrator has configured the policy. There are excellent references on the Internet you can use to see whether your obfuscation technique will work. The free and open source WAF ModSecurity provides a site where you can test the string to see if it might be detected by a WAF. You will find the site at this location http://www.modsecurity.org/demo.

Once the site has opened, you will see that there is an area to post different strings and see the results. Before you do this, you will also see that they have a list of websites that many of the commercial vendors use to demonstrate their tools. An example of this is shown in the following screenshot:

Screen showing a list of the websites that many of the commercial vendors use to demonstrate their tools (the cropped text is not important)

Click on the ModSecurity CRS Evasion...