Joel over at appiant.net has posted a great video of how he used SQL injection to bypass security controls on a college website. While his methods may seem 1-2-3 to web application security testers, they are a great example of just how simple this type of attack is, and a reminder that you MUST perform this same type of testing on EVERY web application you deploy, period. . The link for this article located at IT Toolbox is no longer available. . Delve into the world of buffer overflow exploits with an engaging presentation that highlights penetration tactics and cybersecurity education.. SQL Injection Techniques, Web Security Awareness, Cybersecurity Insights. . LinuxSecurity.com Team
Web application security is interesting to test, in particular because, unlike most network and operating system testing, most web applications are custom-built. Even when they’re not custom-built, there’s enough diversity out there that simply looking for known problems isn’t good enough. You need to review the application itself. . At one of my previous employers, we had a good system for reviewing all web applications with a couple of commercial scanner tools; applications could not be deployed into production until the results of those scans were acceptable. Application scanners do not, of course, catch everything — there are always esoteric conditions that are easily missed in automated tests. Manual testing has an important place in assessments. Automated testing, though, does have a number of advantages. The link for this article located at Caffinated Security is no longer available. . Thorough security evaluation of web applications necessitates both automated tools and human-led assessments to guarantee strong protection against unrecognized threats.. Web Application Testing, Security Tools, Application Scanning. . LinuxSecurity.com Team
Get the latest Linux and open source security news straight to your inbox.