Image
 
linkedin_logo.png rss_logo.jpg
twitter_logo.png youtube_logo.jpg
Latest Additions
 
EH-Net Login
Welcome Guest.






Lost Password?
No account yet? Register
Who's Online
We have 64 guests and 2 members online
 
Advertisement

You are here: Home arrow Ethical Hacking Discussions and Related Certificationsarrow Web Applicationsarrow Just another guy asking suggestions for learning the basics os Web-Exploitation
EH-Net
May 18, 2013, 01:52:28 PM *
Welcome, Guest. Please login or register.
Did you miss your activation email?

Login with username, password and session length
News: Go back to The Ethical Hacker Network Online Magazine Home Page
 
   Home   Help Calendar Login Register  
Pages: [1]   Go Down
  Print  
Author Topic: Just another guy asking suggestions for learning the basics os Web-Exploitation  (Read 3538 times)
0 Members and 1 Guest are viewing this topic.
manoj9372
Jr. Member
**
Offline Offline

Posts: 72


View Profile
« on: November 11, 2010, 03:14:25 AM »

As the title says ,i am looking forward to build some strong base in learning Web-Application hacking and exploitation,

For now i am not looking for advanced stuff such as understanding coding,playing inside xamp and wamp locally,

I am just interested in understanding about the basics of those attacks
and how it works? like that...

for now i am looking specifickly to understand basics of the following,
just basics because once i understood the basics of these attacks,

1)sql
2)blind sqli
3)Directory traversal attacks
4)xss
5)CSRF
6)basics of WAF
7)bacis working operation of shells
8)log-in authentication bypass
9)working of WebApplication firewalls and how it is implemented..

I know for sql and blind sqli i can find lot of materials on here and also on hackforums,but my concern is they are mostly looking forward to attack the site instead of focusing on the basic operations of it works..

So please give me some advice/guidance based on your personal experience,...


Hope i will get some specific advice  Grin


Note:I am not a coder ...
Logged
MindOverMatter
Jr. Member
**
Offline Offline

Posts: 62


View Profile
« Reply #1 on: November 11, 2010, 03:41:01 AM »

Hi manoj9372,

I know you said you wanted some specific advice, so my post may not be much of a help.

However, I can say that some of the best Web-Application content I've seen is the module by Armando at eLearnSecurity..  I'm actually going through it now and it is very good, in depth, yet easy to understand and step by step.

Of course it's not free, other than the SQL Injection portion, but it is worth it in my opinion.  This is coming from someone without a Web Application background, plus many on the forum here have said that it is the strongest compared to other courses.

Just my 2 cents, but hope you get the advice you're looking for.
Logged

A+, Network+, Security+, CIW Associate, CCNA, C|EH
UNIX
Hero Member
*****
Offline Offline

Posts: 1234


View Profile
« Reply #2 on: November 11, 2010, 05:15:11 AM »

I'd recommend "The Web Application Hacker's Handbook: Discovering and Exploiting Security Flaws", which is a great book. As it seems you have very little knowledge in these areas, it's probably too advanced for you at this point, as you should already be familiar with some related topics.

Quote
For now i am not looking for advanced stuff such as understanding coding,playing inside xamp and wamp locally,

I think you got it wrong - attacking systems are not really the basics, but rather are programming, system administration etc. If you are straight going for attacking systems without really understanding how they work, you are missing a very big picture.

Maybe you might read "Hacking For Dummies" which is sometimes recommended here at EH-Net to newcomers. I haven't read it personally though, so I can't affirm this recommendation.
Logged
MaXe
Hero Member
*****
Offline Offline

Posts: 669


I've just upgraded myself to a cyborg muahahaa!!1


View Profile WWW
« Reply #3 on: November 11, 2010, 07:49:43 AM »

This is coming from someone without a Web Application background, plus many on the forum here have said that it is the strongest compared to other courses.

Looks like I have to do some serious work soon then  Grin Something for people already knowing Web App Sec  Wink
Logged

I'm an InterN0T'er
MindOverMatter
Jr. Member
**
Offline Offline

Posts: 62


View Profile
« Reply #4 on: November 11, 2010, 10:51:19 AM »

This is coming from someone without a Web Application background, plus many on the forum here have said that it is the strongest compared to other courses.

Looks like I have to do some serious work soon then  Grin Something for people already knowing Web App Sec  Wink

I'm confused by what you mean, I think I have MatterOverMind, due to some overdosage of morning Cinamon Toast Crunch...
« Last Edit: November 11, 2010, 10:58:40 AM by MindOverMatter » Logged

A+, Network+, Security+, CIW Associate, CCNA, C|EH
MaXe
Hero Member
*****
Offline Offline

Posts: 669


I've just upgraded myself to a cyborg muahahaa!!1


View Profile WWW
« Reply #5 on: November 11, 2010, 03:19:53 PM »

This is coming from someone without a Web Application background, plus many on the forum here have said that it is the strongest compared to other courses.

Looks like I have to do some serious work soon then  Grin Something for people already knowing Web App Sec  Wink

I'm confused by what you mean, I think I have MatterOverMind, due to some overdosage of morning Cinamon Toast Crunch...

Excuse me for being cryptic, what I meant was a course meant for pros at Web App Sec Smiley

I know it sounds cryptic, but hehe nevermind  Grin Forget what I said :-P
Logged

I'm an InterN0T'er
Pages: [1]   Go Up
  Print  
 
Jump to:  

Powered by MySQL Powered by PHP Powered by SMF 1.1.18 | SMF © 2013, Simple Machines
Joomla Bridge by JoomlaHacks.com
Valid XHTML 1.0! Valid CSS!
Page created in 0.063 seconds with 23 queries.
 
Exclusive Deal

sansfire13_245x90_cw90.jpg
SANSFIRE 2013
June 15 - 22

5% Off w/ Code: EHN_5

SANS Deals 4 EH-Netters
5% OFF Any SANS Course in Any Format!
Coupon Code: EHN_5 Including SANS Rocky Mountain 2013 & SANS Boston 2013
Polls
Compared to this year, 2013 will be:
 
Recent Forum Topics
EH-Net News Feeds
Latest Additions
 
         
Free Business and Tech Magazines and eBooks

© 2013 The Ethical Hacker Network
Joomla! is Free Software released under the GNU/GPL License.