Home
Calendar
Certifications
Columns
Features
Forum
Resources
Vitals
Latest Additions
Jan 2009 Free Giveaway Sponsor - Black Hat DC
Scooby Doo and the Crypto Caper - Answers and Winners
Daemon - A Contest Revealed
Hacking: The Art of Exploitation 2nd Edition
Nov 2008 Free Giveaway - Winners
Dec 2008 Free Giveaway Sponsor - SANS
Santa Claus is Hacking to Town
Plug-N-Play Network Hacking
Nov 2008 Free Giveaway Sponsor - CWNP
Daemon - A Contest Begins Now
It Happened One Friday - Answers and Winners
Daemon - A Contest
Scooby Doo and the Crypto Caper
MS Blue Hat Hackers Headline Chicago Security Con
The Pen Testing Perfect Storm Webcast Series with Skoudis, Wright, Johnson
EH-Net Login
Welcome Guest.
Username:
Password:
Remember me
Lost Password?
No account yet?
Register
Who's Online
We have 25 guests and 3 members online
EH-Net Donations
Enter Amount:
$
CAD
USD
GBP
AUD
JPY
EUR
Google Ads
EH-Net News Feeds
Latest Additions
Book Recommendations
You are here:
Home
Forum
Ethical Hacking Discussions and Related Certifications
Web Applications
Web App Hacking
Ethical Hacker Community Forums
January 07, 2009, 11:52:10 PM
Welcome,
Guest
. Please
login
or
register
.
Did you miss your
activation email?
1 Hour
1 Day
1 Week
1 Month
Forever
Login with username, password and session length
News
: ChicagoCon 2-Day Ethical Hacking Conference with MS Blue Hats Oct 31 - Nov 1. Tickets Only $100!
www.chicagocon.com/content/view/103/51/
Home
Help
Calendar
Login
Register
Ethical Hacker Community Forums
>
Ethical Hacking Discussions and Related Certifications
>
Web Applications
(Moderator:
don
) >
Web App Hacking
Pages: [
1
]
Go Down
« previous
next »
Print
Author
Topic: Web App Hacking (Read 6158 times)
0 Members and 1 Guest are viewing this topic.
oleDB
Full Member
Offline
Posts: 231
Web App Hacking
«
on:
August 14, 2008, 08:55:22 AM »
Anybody have a recommendation for a training class and/or book on Web App Hacking?
I was think about buying
The Web Application Hacker's Handbook: Discovering and Exploiting Security Flaws
Logged
vijay2
Full Member
Offline
Posts: 134
Re: Web App Hacking
«
Reply #1 on:
August 14, 2008, 09:36:18 AM »
SANS has a 4-day class
Security 542 Web Application Penetration Testing In-Depth
I have heard good reviews of this class
VJ
Logged
GPEN GCIH CISSP CISA GSEC OSCP C|EH Security+
only_samurai
Newbie
Offline
Posts: 6
Re: Web App Hacking
«
Reply #2 on:
August 14, 2008, 09:40:06 AM »
There are some good books and classes out there, but I've never personally used them. In my opinion, the best way to pick this stuff up is to start coding in a web-language and while you are working on building web-applications, be reading about security. This method won't take you in-depth, but will build a solid baseline to build on top of.
Just my two cents.
-samurai
Logged
oleDB
Full Member
Offline
Posts: 231
Re: Web App Hacking
«
Reply #3 on:
August 14, 2008, 12:32:16 PM »
Samurai,
I agree. I'm trying to build up my skillset in this area, beyond just scanning and exploiting.
VJ,
Are there any instructors that standout? Just wondering as my past experience with SANS was heavily dependent on the which instructor you got. For example, the smaller SANS events usually don't get the A Team.
Logged
don
Editor-In-Chief
Administrator
Hero Member
Offline
Posts: 2435
Editor-In-Chief
Re: Web App Hacking
«
Reply #4 on:
August 14, 2008, 01:32:52 PM »
For SANS, Kevin Johnson is the man:
Quote
Kevin Johnson is a Senior Security Analyst with Intelguardians. Kevin came to security from a development and system administration background. He has many years of experience performing security services for Fortune 100 companies, and in his spare time contributes to a large number of open source security projects. Kevin founded and leads the development on
B.A.S.E. (the Basic Analysis and Security Engine) project
. The BASE project is the most popular web interface for the Snort intrusion detection system. Kevin is an instructor for SANS, teaching both the Incident Handling and Hacker Techniques class and the Web Application Security class. He has presented to many organizations, including Infragard, ISACA, ISSA and the University of Florida.
The
InfoSec Institute
also has some really good web app guys with Jeremy Martin:
Quote
Jeremy Martin, Cyber Warfare Instructor, is a Senior Security Researcher that has focused his work on Red Team penetration testing, Computer Forensics, and Cyber Warfare. Starting his career in 1995 Mr. Martin has worked with fortune 200 companies and Federal Government agencies, receiving a number of awards for service. Jeremy is a published author, teaches, and speaks at security conferences around the world. Current projects include vulnerability analysis, threat profiling, exploitation automation, anti-forensics, and reverse engineering malware. He is active in the Information Security/Assurance world and is the current President for the Open Information Systems Security Group (OISSG) while sitting on the Board of Directors for Denver’s Infragard chapter. Jeremy is also an active member of the Business Espionage Controls & Countermeasures Association.
...and sometimes Andres Andreu, author of
Professional Pen Testing for Web Applications
(In fact this is the course textbook):
Quote
Andres Andreu, CISSP-ISSAP, GSEC currently operates neuroFuzz Application Security LLC, and has a strong background with the U.S. government. He served the United States of America in Information Technology and Security capacities within a “3-Letter” federal law enforcement agency. The bulk of his time there was spent building the IT Infrastructure and working on numerous intelligence software programs for one of the largest Title III Interception Operations within the continental U.S. He worked there for a decade and during that time he was the recipient of numerous agency awards for outstanding performance.
He holds a bachelor’s degree in Computer Science, graduating Summa Cum Laude with a 3.9 GPA from the American College of Computer and Informational Sciences. Mr. Andreu specializes in software, application, and Web services security, working with XML security, TCP and HTTP(S) level proxying technology, and strong encryption. He has many years of experience with technologies like LDAP, Web services (SOA, SOAP, and so on), enterprise applications, and application integration.
Hope this helps,
Don
«
Last Edit: August 14, 2008, 01:34:28 PM by don
»
Logged
CISSP, MCSE, CEH, Security+ SME
BillV
Hero Member
Offline
Posts: 883
Re: Web App Hacking
«
Reply #5 on:
August 14, 2008, 01:37:52 PM »
I will second Don's recommendation of the "Professional PenTesting for Web Applications" book by Andres Andreu.
Additionally, I also have a copy of the book you have referenced, "Web Application Hackers Handbook" and highly recommend that as well. This is a great hands-on complement to something like the OWASP testing guide, including side-notes for step-by-step instructions.
Logged
oleDB
Full Member
Offline
Posts: 231
Re: Web App Hacking
«
Reply #6 on:
August 14, 2008, 02:17:19 PM »
Cool, thanks for the info. I will checkout both of those books at the store to figure out which one to buy online.
Is that Webgoat thing on the OWASP site decent?
Logged
mad_irish
Newbie
Offline
Posts: 16
Re: Web App Hacking
«
Reply #7 on:
August 14, 2008, 02:54:15 PM »
WebGoat is pretty solid, but for my money I'd recommend cruising the vulnerability announcements for well known web apps and installing vulnerable versions and exploiting them yourself. Many of the most popular web systems have vulnerable versions at some point. Installing them and figuring out how to exploit the vulnerability is, I think, a lot more worthwhile than poking at a training application. Of course, you've got a lot more overhead installing and configuring applications that you may not intend to use other than as an exploitation experiment. Just my $.02. Getting familiar with tools like Paros and the Firefox Tamper Data plugin will go a long way towards getting you up to speed also.
Logged
only_samurai
Newbie
Offline
Posts: 6
Re: Web App Hacking
«
Reply #8 on:
August 14, 2008, 03:33:46 PM »
I personally don't like projects like WebGoat. The pre-fabricated exploit environments always seem a little too fake for my tastes and I find that many of the exploits you work with in them are either overly basic or purely theoretical. Meaning, you either do something you already know or you are working with something that you'll almost never see in practice.
I would completely agree with finding a vulnerable piece of software and using that. An open-sourced CMS or something like PHPBB would be good to work with. Set-up on some of these is very quick and easy and then would let you work with actually exploiting the code.
Just my thoughts...
-samurai
Logged
vijay2
Full Member
Offline
Posts: 134
Re: Web App Hacking
«
Reply #9 on:
August 15, 2008, 05:50:21 AM »
OleDB,
As Don mentioned, for SANS Kevin Johnson is the man.
VJ
Logged
GPEN GCIH CISSP CISA GSEC OSCP C|EH Security+
Mansa
Newbie
Offline
Posts: 2
Re: Web App Hacking
«
Reply #10 on:
August 16, 2008, 08:55:57 AM »
Quote from: vijay2 on August 14, 2008, 09:36:18 AM
SANS has a 4-day class
Security 542 Web Application Penetration Testing In-Depth
I have heard good reviews of this class
VJ
Regarding the SANS classes, how big are the classes and do they have a classroom feel or more of a seminar feel?
Logged
vijay2
Full Member
Offline
Posts: 134
Re: Web App Hacking
«
Reply #11 on:
August 16, 2008, 10:18:50 PM »
Depending upon the conference and popularity of class and instructor, the class can be between 25 to 60 people.
Hope that helps
VJ
Logged
GPEN GCIH CISSP CISA GSEC OSCP C|EH Security+
Mansa
Newbie
Offline
Posts: 2
Re: Web App Hacking
«
Reply #12 on:
August 21, 2008, 05:43:14 PM »
Quote from: vijay2 on August 16, 2008, 10:18:50 PM
Depending upon the conference and popularity of class and instructor, the class can be between 25 to 60 people.
Hope that helps
VJ
Whoa, up to 60 people. Who are the other reputable training providers out there?
Logged
oleDB
Full Member
Offline
Posts: 231
Re: Web App Hacking
«
Reply #13 on:
August 27, 2008, 09:25:26 AM »
Also, between SANS and the Infosec Institute, which one has more hands-on activities? And do either use Core-Impact and/or Canvas during the class?
Logged
Pages: [
1
]
Go Up
Print
« previous
next »
Jump to:
Please select a destination:
-----------------------------
EH-Net
-----------------------------
=> Special Events
=> Calendar Of Events
===> ChicagoCon 2007
===> ChicagoCon 2008s
===> ChicagoCon 2008f
===> ChicagoCon 2009
=> News Items and General Discussion About EH-Net
-----------------------------
Ethical Hacking Discussions and Related Certifications
-----------------------------
=> Certification
===> The Charter Study Group - Pen Test
=> Network Pen Testing
===> CEH - Certified Ethical Hacker
=====> CEH - Official Course Modules v4
=====> CEH - Official Course Modules v5
=====> CEH - Official Course Modules v6
===> CPTS - Certified Pen Testing Specialist
=====> CPTS - Official Course Modules v5
===> CPTE - Certified Pen Testing Expert
=====> CPTE - Official Course Modules v1
===> ECSA - EC-Council Certified Security Analyst
=====> ECSA - Official Course Modules v1.2
=====> ECSA / LPT - Official Course Modules v3
===> OSCP - Offensive Security Certified Professional
===> GPEN - GIAC Certified Penetration Tester
=> Forensics
===> CCE / MCCE - (Master) Certified Computer Examiner
===> CHFI - Computer Hacking Forensic Investigator
=====> CHFI - Official Course Modules v2
===> EnCE - EnCase® Certified Examiner
=> Incident Response
===> CSIH - Computer Security Incident Handler
===> GCIH - GIAC Certified Incident Handler
=> Hardware
=> Malware
=> Physical Security
=> Programming
=> Social Engineering
=> Web Applications
=> Wireless
===> CWNP Certs
===> GAWN - GIAC Assessing Wireless Networks
===> OSWP - Offensive Security Wireless Professional
=> Other
-----------------------------
Columns
-----------------------------
=> Editor-In-Chief
=> Gates
=> Heffner
=> Hoffman
=> RichM
=> Murray
=> J. Peltier
=> Wilson
-----------------------------
Features
-----------------------------
=> /root
=> Book Reviews
=> Opinions
=> Skillz
===> Examples
===> May 06 - Star Hacks, Episode V: The Empire Hacks Back
===> July 06 - Hack Bill!
===> Sept 06 - Netcat in the Hat
===> Nov 06 - Hitch-Hackers Guide to the Galaxy
===> Dec 06 - A Christmas (Hacking) Story
===> Feb 07 - Charlottes Web Site
===> April 07 - Microsoft Office Space
===> June 07 - Serenity Hack
===> Oct 07 - Worst. Ethical. Hacker. Challenge. Ever.
===> Dec 07 - Frosty the Snow Crash
===> March 2008 - It Happened One Friday
===> Oct 2008 - Scooby Doo and the Crypto Caper
===> Dec 08 - Santa Claus Is Hacking to Town
-----------------------------
Resources
-----------------------------
=> Career Central
===> Looking For Work
===> Looking To Hire
=> Links to cool sites.
=> Mass Media
=> News from the Outside World
=> Tools
=> Tutorials
Loading...
Sponsors
Polls
How many security events including conferences and training do you attend a year:
1 - 2
3 - 4
5 - 6
7+
None - But want to
None - Choose not to
Support EH-Net
Support EH-Net by
Buying all of your
Amazon items using
the search bar above.
Try CBT Nuggets Free!
Recent Forum Topics
Malware
: Security Forecast for 2009
(5) by
jason
Mass Media
: Daniel Suarez Interview
(8) by
jason
News from the Outside World
: Is this acceptable?
(9) by
jason
Wireless
: Wireless Pen Testing Cards
(6) by
jason
CEH - Certified Ethical Hacker
: CEH is a scam
(19) by
jason
Oct 2008 - Scooby Doo and the Crypto Caper
: Skillz October 08 Winning Entry - Technical
(1) by
jason
Gates
: Oracle version module for metasploit
(2) by
BillV
Book Reviews
: [Article]-Mitnick - The Art Of Intrusion: Ch 1 - Hacking The Casinos For A Million Bu...
(5) by
jason
Links to cool sites.
: Free Computer Engineering Classes From Stanford
(3) by
jason
Oct 2008 - Scooby Doo and the Crypto Caper
: Skillz October 08 Winning Entry - Creative
(1) by
jason
Oct 2008 - Scooby Doo and the Crypto Caper
: [Article]-Scooby Doo and the Crypto Caper - Answers and Winners
(2) by
jason
News Items and General Discussion About EH-Net
: [Article]-Jan 2009 Free Giveaway Sponsor - Black Hat DC
(1) by
jason
Book Reviews
: Need a book suggestion!
(2) by
jason
News Items and General Discussion About EH-Net
: EH-Net Milestone - 2 Articles Cross 1 Million Page Views
(3) by
BillV
Other
: What kind of lab, machines you have for your security testing?
(12) by
charlottebandit
Malware
: Network Virus Problem
(9) by
RoleReversal
Wireless
: WUSB600N good usb ?
(2) by
nap191
Other
: FBI code cracking challenge
(3) by
jimbob
Calendar Of Events
: RSA 2009
(0) by
don
Forensics
: Network Forensic tools/practice/techniques
(2) by
jimbob
Malware
: Autoplay when i try to open the drive.
(4) by
jimbob
Physical Security
: Magnetic stripe card spoofing
(4) by
jimbob
Malware
: THe website is Evil but what to do??
(1) by
jimbob
Other
: Insanity?
(3) by
jason
CEH - Certified Ethical Hacker
: Any Practice Environment for learning tool for CEH?
(15) by
don
Wireless
: a petri-dish bridge
(2) by
don
CEH - Certified Ethical Hacker
: TFTP Tranfer time out
(5) by
jason
Tools
: tool to trace users
(8) by
pseud0
Malware
: Malware Challenge 2008 Analysis
(0) by
blackazarro
Programming
: Python 3.0 Released
(0) by
don
Forensics
: SANS SIFT Forensic toolkit
(1) by
don
Links to cool sites.
: Omgili Hacking - Another Search Engine dedicated to Hacking Related Forums
(2) by
RoleReversal
Tools
: Insecure.org's 2006 Top 100 Security Tools List Released
(10) by
shednik
Other
: Happy New Year!
(8) by
vijay2
CEH - Official Course Modules v6
: Community-built CEH Wiki
(2) by
yehg
Vote For EH-Net
progenic.com
binarica.com
technorati fave
Privacy Notice
for TDCC & All Properties
© 2009 The Ethical Hacker Network
Joomla!
is Free Software released under the GNU/GPL License.