Book Image

Python Penetration Testing Essentials - Second Edition

By : Mohit Raj
Book Image

Python Penetration Testing Essentials - Second Edition

By: Mohit Raj

Overview of this book

This book gives you the skills you need to use Python for penetration testing (pentesting), with the help of detailed code examples. We start by exploring the basics of networking with Python and then proceed to network hacking. Then, you will delve into exploring Python libraries to perform various types of pentesting and ethical hacking techniques. Next, we delve into hacking the application layer, where we start by gathering information from a website. We then move on to concepts related to website hacking—such as parameter tampering, DDoS, XSS, and SQL injection. By reading this book, you will learn different techniques and methodologies that will familiarize you with Python pentesting techniques, how to protect yourself, and how to create automated programs to find the admin console, SQL injection, and XSS attacks.
Table of Contents (11 chapters)

Hardening of a web server

In this section, let's shed some light on common mistakes observed on a web server. We will also discuss some points to harden the web server:

  • Always hide your server signature.
  • If possible, set a fake server signature to mislead attackers.
  • Handle the errors.
  • If possible, use a virtual environment (jailing) to run the application.
  • Try to hide the programming language page extensions, because it will be difficult for the attacker to see the programming language of the web applications.
  • Update the web server with the latest patch from the vendor. It avoids any chance of exploitation of the web server. The server can at least be secured for known vulnerabilities.
  • Don't use a third-party patch to update the web server. A third-party patch may contain trojans or viruses.
  • Do not install other applications on the web server. If you install an OS,...