Chapter 13

Web Application Attack Techniques

Abstract

This chapter examines different types of Web application attacks, which can allow the professional penetration tester to access information within backend databases or access-restricted areas. Common attack vectors discussed within include SQL injection, Cross-Site Scripting, Web application vulnerabilities, and the use of automated tools.

Keywords

SQL

Cross-Site Scripting

XSS

Brute force

Web

Database

Contents

Chapter Points

 SQL Injection

 Cross-Site Scripting

 Web Application Vulnerabilities

 Automated Tools

Introduction

One very popular attack vector targets Web sites. In external ...

Get Professional Penetration Testing, 2nd Edition now with the O’Reilly learning platform.

O’Reilly members experience books, live events, courses curated by job role, and more from O’Reilly and nearly 200 top publishers.