Answer the question
In order to leave comments, you need to log in
Where can I read about auditing the information security of a web application?
Good evening!
Now there are many services for auditing the information security of websites / applications, where can I read about their activities? What exactly do they check and how? I've only found this so
far .
Ideally, I would like to read articles, perhaps even with examples, on how to find this or that vulnerability on a website.
I will add that the black box method is preferable (I do not have access to the files of the server where the site is located)
Answer the question
In order to leave comments, you need to log in
In general, you hit the mark, that is, this is the most (well, one of the most - that's for sure) "shared" site on web application security, there are many all sorts of projects that in one way or another relate to the security of the web.
But in your case, you need to look at this project on web application penetration testing for vulnerabilities (that is, by detection). That project has a guide in pdf format (relatively fresh), where everything is very well and conveniently described, it describes all types of vulnerabilities, how to look for them (both black and gray boxes are described), how they can then be promoted, links to additional articles and, of course, tools/services to automate and help detect those vulnerabilities.
There are also articles on the site (sometimes even separate projects) on some types of vulnerabilities, it will also be interesting to read.
From CGI scanners, you can select Acunetix Web Vulnerability Scanner (but paid, dog, although the torrent is helpful), you can also see ZAP from the participants of the same OWSAP'a.
As for services: if it’s about online scanners, then, as a rule, working methods are not disclosed (especially if they are commercial), but open source scanners always have manuals on the principles of their work, but I want to note that such scanners usually reveal trivial vulnerabilities and studying their work is very won't give much in web application pentesting. If you meant services, like teams of specialists who conduct audits, then of course they don’t disclose this either, but there are organizations (as described above - OWASP) that are created just to share information and describe all kinds of techniques and tricks for the detection and exploitation of vulnerabilities, in addition to such organizations, you can learn a lot of useful information on the relevant forums (RDot.org, for example).
Didn't find what you were looking for?
Ask your questionAsk a Question
731 491 924 answers to any question