Book Image

Kali Linux Intrusion and Exploitation Cookbook

By : Dhruv Shah, Ishan Girdhar
Book Image

Kali Linux Intrusion and Exploitation Cookbook

By: Dhruv Shah, Ishan Girdhar

Overview of this book

With the increasing threats of breaches and attacks on critical infrastructure, system administrators and architects can use Kali Linux 2.0 to ensure their infrastructure is secure by finding out known vulnerabilities and safeguarding their infrastructure against unknown vulnerabilities. This practical cookbook-style guide contains chapters carefully structured in three phases – information gathering, vulnerability assessment, and penetration testing for the web, and wired and wireless networks. It's an ideal reference guide if you’re looking for a solution to a specific problem or learning how to use a tool. We provide hands-on examples of powerful tools/scripts designed for exploitation. In the final section, we cover various tools you can use during testing, and we help you create in-depth reports to impress management. We provide system engineers with steps to reproduce issues and fix them.
Table of Contents (18 chapters)
Title Page
Credits
About the Authors
About the Reviewers
www.PacktPub.com
Customer Feedback
Preface

Using sqlmap to find SQL Injection on the login page


SQL Injections are always in the OWASP top three in every iteration of OWASP Web Top 10 Vulnerabilities for a reason. They are the most damaging to web applications and thus to businesses as well. Finding an SQL Injection is difficult, but if you happen to find one, exploiting it manually till you get access on the server is even harder and time consuming. Therefore, it is important to use an automated approach because during the penetration testing activity, time is always running out and you will always want to confirm the existence of an SQL Injection sooner than later.

Sqlmap is an open source penetration testing tool that automates the process of detecting and exploiting SQL Injection flaws and taking over of database servers written in Python and being regularly maintained by their developers. SQLMap has become a powerful tool and is very reliable in identifying and detecting SQL Injection in various parameters.

In this recipe, we...