2. Perform Web applications Attacks
An ethical hacker or pen tester must test their company’s web application against various attacks and other vulnerabilities.
1. Brute force using Burp
Hydra Brute force cheatsheat
2. Parameter tampering using Burp

3. Identify XSS using PwnXss

4. Exploit Parameter tempering with XSS
5. Perform CSRF attacks
6. Hack a wordpress site with WPSCAN and Metasploit
Installation


WPSCAN brute forcing
Reference
7. Remote command execution to compromise a target server
Windows Command Injection
8. Exploit File upload vulnerability
9. Exploit Log4j vulnerability
10. Perform Remote Code Execution (RCE) Attack
Previous1. Footprint the Web InfrastructureNext3. Detect Web Vulnerabilities using using web application security tools
Last updated





