Image
 
Latest Additions
 
EH-Net Login
Welcome Guest.






Lost Password?
No account yet? Register
Who's Online
We have 24 guests online
EH-Net Donations

Enter Amount:
$

Google Ads
EH-Net News Feeds
Latest Additions
Book Recommendations





 
Advertisement

You are here: Home arrow Forum arrow Ethical Hacking Discussions and Related Certificationsarrow Web Applicationsarrow Web App Hacking
Ethical Hacker Community Forums
December 05, 2008, 05:09:26 AM *
Welcome, Guest. Please login or register.
Did you miss your activation email?

Login with username, password and session length
News: ChicagoCon 2-Day Ethical Hacking Conference with MS Blue Hats Oct 31 - Nov 1. Tickets Only $100! www.chicagocon.com/content/view/103/51/
 
   Home   Help Calendar Login Register  
Pages: [1]   Go Down
  Print  
Author Topic: Web App Hacking  (Read 5714 times)
0 Members and 1 Guest are viewing this topic.
oleDB
Full Member
***
Offline Offline

Posts: 231



View Profile WWW
« on: August 14, 2008, 08:55:22 AM »

Anybody have a recommendation for a training class and/or book on Web App Hacking?

I was think about buying
The Web Application Hacker's Handbook: Discovering and Exploiting Security Flaws
Logged
vijay2
Full Member
***
Offline Offline

Posts: 127


View Profile
« Reply #1 on: August 14, 2008, 09:36:18 AM »

SANS has a 4-day class

Security 542 Web Application Penetration Testing In-Depth

I have heard good reviews of this class

VJ
Logged

GPEN GCIH CISSP GSEC OSCP C|EH MCSE CNE Security+
only_samurai
Newbie
*
Offline Offline

Posts: 6


View Profile WWW
« Reply #2 on: August 14, 2008, 09:40:06 AM »

There are some good books and classes out there, but I've never personally used them. In my opinion, the best way to pick this stuff up is to start coding in a web-language and while you are working on building web-applications, be reading about security. This method won't take you in-depth, but will build a solid baseline to build on top of.

Just my two cents.
-samurai
Logged
oleDB
Full Member
***
Offline Offline

Posts: 231



View Profile WWW
« Reply #3 on: August 14, 2008, 12:32:16 PM »

Samurai,
I agree. I'm trying to build up my skillset in this area, beyond just scanning and exploiting.

VJ,
Are there any instructors that standout? Just wondering as my past experience with SANS was heavily dependent on the which instructor you got. For example, the smaller SANS events usually don't get the A Team.
Logged
don
Editor-In-Chief
Administrator
Hero Member
*****
Offline Offline

Posts: 2384


Editor-In-Chief


View Profile WWW
« Reply #4 on: August 14, 2008, 01:32:52 PM »

For SANS, Kevin Johnson is the man:

Quote
Kevin Johnson is a Senior Security Analyst with Intelguardians. Kevin came to security from a development and system administration background. He has many years of experience performing security services for Fortune 100 companies, and in his spare time contributes to a large number of open source security projects. Kevin founded and leads the development on B.A.S.E. (the Basic Analysis and Security Engine) project. The BASE project is the most popular web interface for the Snort intrusion detection system. Kevin is an instructor for SANS, teaching both the Incident Handling and Hacker Techniques class and the Web Application Security class. He has presented to many organizations, including Infragard, ISACA, ISSA and the University of Florida.

The InfoSec Institute also has some really good web app guys with Jeremy Martin:

Quote
Jeremy Martin, Cyber Warfare Instructor, is a Senior Security Researcher that has focused his work on Red Team penetration testing, Computer Forensics, and Cyber Warfare.  Starting his career in 1995 Mr. Martin has worked with fortune 200 companies and Federal Government agencies, receiving a number of awards for service.  Jeremy is a published author, teaches, and speaks at security conferences around the world.  Current projects include vulnerability analysis, threat profiling, exploitation automation, anti-forensics, and reverse engineering malware. He is active in the Information Security/Assurance world and is the current President for the Open Information Systems Security Group (OISSG) while sitting on the Board of Directors for Denver’s Infragard chapter.  Jeremy is also an active member of the Business Espionage Controls & Countermeasures Association.

...and sometimes Andres Andreu, author of Professional Pen Testing for Web Applications (In fact this is the course textbook):

Quote
Andres Andreu, CISSP-ISSAP, GSEC currently operates neuroFuzz Application Security LLC, and has a strong background with the U.S. government. He served the United States of America in Information Technology and Security capacities within a “3-Letter” federal law enforcement agency. The bulk of his time there was spent building the IT Infrastructure and working on numerous intelligence software programs for one of the largest Title III Interception Operations within the continental U.S. He worked there for a decade and during that time he was the recipient of numerous agency awards for outstanding performance.

He holds a bachelor’s degree in Computer Science, graduating Summa Cum Laude with a 3.9 GPA from the American College of Computer and Informational Sciences. Mr. Andreu specializes in software, application, and Web services security, working with XML security, TCP and HTTP(S) level proxying technology, and strong encryption. He has many years of experience with technologies like LDAP, Web services (SOA, SOAP, and so on), enterprise applications, and application integration.

Hope this helps,
Don
« Last Edit: August 14, 2008, 01:34:28 PM by don » Logged

CISSP, MCSE, CEH, Security+ SME
BillV
Hero Member
*****
Offline Offline

Posts: 870


View Profile
« Reply #5 on: August 14, 2008, 01:37:52 PM »

I will second Don's recommendation of the "Professional PenTesting for Web Applications" book by Andres Andreu.

Additionally, I also have a copy of the book you have referenced, "Web Application Hackers Handbook" and highly recommend that as well. This is a great hands-on complement to something like the OWASP testing guide, including side-notes for step-by-step instructions.
Logged
oleDB
Full Member
***
Offline Offline

Posts: 231



View Profile WWW
« Reply #6 on: August 14, 2008, 02:17:19 PM »

Cool, thanks for the info. I will checkout both of those books at the store to figure out which one to buy online.

Is that Webgoat thing on the OWASP site decent?
Logged
mad_irish
Newbie
*
Offline Offline

Posts: 16



View Profile WWW
« Reply #7 on: August 14, 2008, 02:54:15 PM »

WebGoat is pretty solid, but for my money I'd recommend cruising the vulnerability announcements for well known web apps and installing vulnerable versions and exploiting them yourself.  Many of the most popular web systems have vulnerable versions at some point.  Installing them and figuring out how to exploit the vulnerability is, I think, a lot more worthwhile than poking at a training application.  Of course, you've got a lot more overhead installing and configuring applications that you may not intend to use other than as an exploitation experiment.  Just my $.02.  Getting familiar with tools like Paros and the Firefox Tamper Data plugin will go a long way towards getting you up to speed also.
Logged
only_samurai
Newbie
*
Offline Offline

Posts: 6


View Profile WWW
« Reply #8 on: August 14, 2008, 03:33:46 PM »

I personally don't like projects like WebGoat. The pre-fabricated exploit environments always seem a little too fake for my tastes and I find that many of the exploits you work with in them are either overly basic or purely theoretical. Meaning, you either do something you already know or you are working with something that you'll almost never see in practice.

I would completely agree with finding a vulnerable piece of software and using that. An open-sourced CMS or something like PHPBB would be good to work with. Set-up on some of these is very quick and easy and then would let you work with actually exploiting the code.

Just my thoughts...
-samurai
Logged
vijay2
Full Member
***
Offline Offline

Posts: 127


View Profile
« Reply #9 on: August 15, 2008, 05:50:21 AM »

OleDB,

As Don mentioned, for SANS Kevin Johnson is the man.

VJ
Logged

GPEN GCIH CISSP GSEC OSCP C|EH MCSE CNE Security+
Mansa
Newbie
*
Offline Offline

Posts: 2


View Profile
« Reply #10 on: August 16, 2008, 08:55:57 AM »

SANS has a 4-day class

Security 542 Web Application Penetration Testing In-Depth

I have heard good reviews of this class

VJ

Regarding the SANS classes, how big are the classes and do they have a classroom feel or more of a seminar feel?
Logged
vijay2
Full Member
***
Offline Offline

Posts: 127


View Profile
« Reply #11 on: August 16, 2008, 10:18:50 PM »

Depending upon the conference and popularity of class and instructor, the class can be between 25 to 60 people.

Hope that helps

VJ
Logged

GPEN GCIH CISSP GSEC OSCP C|EH MCSE CNE Security+
Mansa
Newbie
*
Offline Offline

Posts: 2


View Profile
« Reply #12 on: August 21, 2008, 05:43:14 PM »

Depending upon the conference and popularity of class and instructor, the class can be between 25 to 60 people.

Hope that helps

VJ

Whoa, up to 60 people.  Who are the other reputable training providers out there?
Logged
oleDB
Full Member
***
Offline Offline

Posts: 231



View Profile WWW
« Reply #13 on: August 27, 2008, 09:25:26 AM »

Also, between SANS and the Infosec Institute, which one has more hands-on activities? And do either use Core-Impact and/or Canvas during the class?
Logged
Pages: [1]   Go Up
  Print  
 
Jump to:  

Powered by MySQL Powered by PHP Powered by SMF 1.1.7 | SMF © 2006-2008, Simple Machines LLC
Joomla Bridge by JoomlaHacks.com
Valid XHTML 1.0! Valid CSS!
Page created in 0.054 seconds with 23 queries.
 
Sponsors

cwnp_moto__120x90.gif

Polls
During the most recent election, I:
 
Support EH-Net


Support EH-Net by
Buying all of your
Amazon items using
the search bar above.

cbtnuggets_logo_125.jpg
Try CBT Nuggets Free!
Recent Forum Topics
Vote For EH-Net

progenic.com
Click here to Vote!

Sadikhov.com
Top IT Cert Sites

binarica.com
Binarica Logo

Add to Technorati Favorites
technorati fave

 
         
Advertisement

© 2008 The Ethical Hacker Network
Joomla! is Free Software released under the GNU/GPL License.