Home
Calendar
Certifications
Columns
Features
Forum
Resources
Vitals
Latest Additions
April 2013 Free Giveaway Sponsor - eLearnSecurity
Human Intelligence to Navigate the Security Data Deluge
February 2013 Free Giveaway Winner of SANS CyberCon Training
Interview: Bugcrowd Founders on Herding Ninjas for Crowdsourced Bug Bounties
Network Forensics: The Tree in the Forest
March 2013 Free Giveaway Sponsor - Mile2
Book Review: Violent Python
February 2013 Free Giveaway Sponsor - SANS
Holiday 2012 Free Giveaway Winner of Metasploit Pro by Rapid7
Course Review: SANS FOR408 Computer Forensic Investigations – Windows In-Depth
The Security Consulting Sugar High
Tutorial: Fun with SMB on the Command Line
Interview: Ilia Kolochenko, CEO of High-Tech Bridge
October 2012 Free Giveaway Winner of LearningGate Training
The Broken: Assessing Corporate Security in 2012 to Make a Better 2013
EH-Net Login
Welcome Guest.
Username:
Password:
Remember me
Lost Password?
No account yet?
Register
Who's Online
We have 65 guests and 1 member online
You are here:
EH-Net
May 19, 2013, 07:08:25 AM
Welcome,
Guest
. Please
login
or
register
.
Did you miss your
activation email?
1 Hour
1 Day
1 Week
1 Month
Forever
Login with username, password and session length
News
: Go back to The Ethical Hacker Network Online Magazine
Home Page
Home
Help
Calendar
Login
Register
EH-Net
>
Ethical Hacking Discussions and Related Certifications
>
Web Applications
(Moderator:
don
) >
Start into Web Application Security
Pages: [
1
]
Go Down
« previous
next »
Print
Author
Topic: Start into Web Application Security (Read 4221 times)
0 Members and 1 Guest are viewing this topic.
birdofbeauty11
Newbie
Offline
Posts: 7
Start into Web Application Security
«
on:
January 14, 2013, 11:38:21 PM »
Hi,
I am trying to enter into the web application security field. I am somewhat overwhelemed because I have A LOT of vulnerable web applications (OWASP Broken Web Apps, OWASP Security Shepherd, PenTestLab), and I also enrolled in eLearnSecurity and PenTestLab.
My question is, for those in this field, what where your first steps? I clearly have a lot of information (see paragraph above), but I feel like I am not using my time in the most effective manner.
Also, I have a blog passionforpentesting.wordpress.com. I am trying to revitlize the blog again this year, and my goal is to have it as an interactive place for people who want to enter this field. If you can please go to the site (I must warn you in advance the posts are pretty bare), and give suggestions that would be great!
I should re-iterate I REALLY want to transition over to this field, as I am a Application Developer now. This isn't a hobby that I will drop in two months, I've been trying to get into this field for over 2 years, and it seems I am always meet with a brick wall...
Thanks!
Logged
cd1zz
Hero Member
Offline
Posts: 561
Re: Start into Web Application Security
«
Reply #1 on:
January 15, 2013, 09:15:21 AM »
Go get the web application hackers handbook and read it cover to cover. You'll get an idea of "where to look and what to look for" when testing web apps.
Logged
OSCE | OSCP | GXPN | OSWP | CISSP
http://www.pwnag3.com
http://www.networkadminsecrets.com
H1t M0nk3y
Hero Member
Offline
Posts: 864
Re: Start into Web Application Security
«
Reply #2 on:
January 15, 2013, 10:26:55 AM »
Hi birdofbeauty11 and welcome to the forum.
I have more or less the same problem as you. I am a Java system architect who is working very hard to transition into information security.
For me, I find it tough to only do web application pentests. Because other then for huge companies, there isn't enough web apps to justify a full time employee.
In addition, hacking web apps usually requires at least some knowledge of the OS and the network.
I am still mainly working in web apps development, but I do all the security of the apps around me. So I spend about 15% of my time on security. I also train the other developers.
So that's where I am at.
Logged
OSCP, GPEN, GWAPT, GSEC, CEH, CISSP
Grendel
Full Member
Offline
Posts: 239
Re: Start into Web Application Security
«
Reply #3 on:
January 15, 2013, 10:39:17 AM »
While I agree that you should (will) be spending a lot of time researching about web pentesting over your career (especially at the beginning), if you want a place to start you should check out WebGoat (
https://www.owasp.org/index.php/Category:OWASP_WebGoat_Project
).
Not only is this an exploitable image that is geared towards web applications, it's designed for all levels of expertise. The additional advantage is it'll let you know if you really want to pursue the field of web pentesting - if you can handle web goat for more than a week of exercises (WITHOUT looking up the answers), you'll probably be fine in the field.
Logged
- Thomas Wilhelm, MSCS MSM
ISSMP CISSP SCSECA SCNA IEM
Web Site:
http://HackingDojo.com
Author:
Professional Penetration Testing
Ninja Hacking
Penetration Tester's Open Source Toolkit
Metasploit Toolkit for Penetration Testing
Netcat Power Tools
birdofbeauty11
Newbie
Offline
Posts: 7
Re: Start into Web Application Security
«
Reply #4 on:
January 15, 2013, 10:17:32 PM »
Thanks everone for responding!
I'm glad that I am not in this boat alone. (0:
Just a quick note, I do have the "Web Application Handbook" (all 600+ pages of it), but haven't had a chance to sit down and read it. I am more of a hands-on type of learner, so that is why I wanted to start poking around some vulnerable apps.
Quote from: Grendel on January 15, 2013, 10:39:17 AM
While I agree that you should (will) be spending a lot of time researching about web pentesting over your career (especially at the beginning), if you want a place to start you should check out WebGoat (
https://www.owasp.org/index.php/Category:OWASP_WebGoat_Project
).
Not only is this an exploitable image that is geared towards web applications, it's designed for all levels of expertise. The additional advantage is it'll let you know if you really want to pursue the field of web pentesting - if you can handle web goat for more than a week of exercises (WITHOUT looking up the answers), you'll probably be fine in the field.
To answer the block above, I guess I am not cut out for Web App security. I have WebGoat and it is not intuitive to me at all. I often find myself VERY confused when trying to work on the exercises because the instructions do not seem very clear to me. I try to do the exercises without BurpSuite or OWASP ZAP because I want to gain the actually learning without relying on the tools.
Also, to piggy-back, what other areas of security are you guys (or gals) looking at? The reason I picked web app security was because it seemed the most interesting to me, with network security being in second.
I just feel like I am putting WAY too much pressure on myself.
Please respond when able.
Thanks.
Logged
ajohnson
Recruiters
Hero Member
Offline
Posts: 1056
aka dynamik
Re: Start into Web Application Security
«
Reply #5 on:
January 15, 2013, 10:43:16 PM »
I personally haven't used WebGoat, but I've heard many people state it is not intuitive. He may have been referring more to patience, persistence, and perseverance. Web app testing can be frustrating as hell...
Regarding WAHH, there are corresponding labs at mdsec.net. They're not free, but $7/hr is entirely affordable. I just wish you didn't have to use one-hour blocks all at once since it would be nice to try an exercise or two and then get back to reading.
Mutillidae might be a better staring place for you:
http://www.irongeek.com/i.php?page=mutillidae/mutillidae-deliberately-vulnerable-php-owasp-top-10
There are also over 80 videos that walk you through various tasks:
http://www.irongeek.com/i.php?page=videos/web-application-pen-testing-tutorials-with-mutillidae
I think things will become intuitive for you quickly enough, especially if you have a development background.
Logged
WIP: GCFA |
www.infosiege.net
| @infosiege
The day you stop learning is the day you start becoming obsolete.
H1t M0nk3y
Hero Member
Offline
Posts: 864
Re: Start into Web Application Security
«
Reply #6 on:
January 16, 2013, 08:16:55 AM »
Quote
I try to do the exercises without BurpSuite or OWASP ZAP because I want to gain the actually learning without relying on the tools.
So you know birdofbeauty11, many WebGoat exercises requires a web proxy. You don't need to use the burpsuite, but you need a web proxy at the minimum...
WebGoat is not always easy, but I really like it. I found it to be too "cheezy" for teaching people new to security (they think it doesn't represent a real life scenario), but I have learned a lot by looking at... the answers.
I want to back to it again and this time, not look at the answers at all. But this is nevertheless a great tool !
Logged
OSCP, GPEN, GWAPT, GSEC, CEH, CISSP
birdofbeauty11
Newbie
Offline
Posts: 7
Re: Start into Web Application Security
«
Reply #7 on:
January 16, 2013, 07:39:06 PM »
Quote from: ajohnson on January 15, 2013, 10:43:16 PM
I personally haven't used WebGoat, but I've heard many people state it is not intuitive. He may have been referring more to patience, persistence, and perseverance. Web app testing can be frustrating as hell...
Regarding WAHH, there are corresponding labs at mdsec.net. They're not free, but $7/hr is entirely affordable. I just wish you didn't have to use one-hour blocks all at once since it would be nice to try an exercise or two and then get back to reading.
Mutillidae might be a better staring place for you:
http://www.irongeek.com/i.php?page=mutillidae/mutillidae-deliberately-vulnerable-php-owasp-top-10
There are also over 80 videos that walk you through various tasks:
http://www.irongeek.com/i.php?page=videos/web-application-pen-testing-tutorials-with-mutillidae
I think things will become intuitive for you quickly enough, especially if you have a development background.
Thanks for the response. I am trying to learn for free. LOL. I already signed up for eLearnSecurity. I need to build myself up, before I will attempt the exercises in WAHH.
Logged
birdofbeauty11
Newbie
Offline
Posts: 7
Re: Start into Web Application Security
«
Reply #8 on:
January 16, 2013, 07:43:09 PM »
Quote from: H1t M0nk3y on January 16, 2013, 08:16:55 AM
Quote
I try to do the exercises without BurpSuite or OWASP ZAP because I want to gain the actually learning without relying on the tools.
So you know birdofbeauty11, many WebGoat exercises requires a web proxy. You don't need to use the burpsuite, but you need a web proxy at the minimum...
WebGoat is not always easy, but I really like it. I found it to be too "cheezy" for teaching people new to security (they think it doesn't represent a real life scenario), but I have learned a lot by looking at... the answers.
I want to back to it again and this time, not look at the answers at all. But this is nevertheless a great tool !
Thanks for the response! I will try to use WebGoat with a proxy. I have OWASP ZAP proxy installed on my computer. I will try that.
I will try Mulltidae first, and build myself up.
Can you explain what you did to get started in web application security or computer security, period.
Logged
H1t M0nk3y
Hero Member
Offline
Posts: 864
Re: Start into Web Application Security
«
Reply #9 on:
January 17, 2013, 08:03:14 AM »
Quote
Can you explain what you did to get started in web application security or computer security, period.
Personally, I study really hard to be the best (or close to) in my city. Then I go to ISSA, OWASP, etc meetings in my area to make contacts. I also did a few Capture the flag (CTF) competitions.
I believe that if you are very good at something AND paople know you exist, then you will find work.
But nothing's easy...
Logged
OSCP, GPEN, GWAPT, GSEC, CEH, CISSP
MaXe
Hero Member
Offline
Posts: 669
I've just upgraded myself to a cyborg muahahaa!!1
Re: Start into Web Application Security
«
Reply #10 on:
January 18, 2013, 08:44:21 AM »
In case you haven't, check out my web app sec blog series:
www.exploit-db.com/category/maxe/
The best way to learn web app sec, is to learn a language such as PHP (knowing HTML, CSS and basic Javascript is elementary), and then understand why these bugs exist, how they look code-wise, and how to fix them. That way you can patch bugs, find 0days more easily, and know more. Or even create your own web app sec labs, which I've done for a few on a project basis sometime ago.
Take a look at this thread:
http://forum.intern0t.org/offensive-guides-information/1382-finding-vulnerabilities-php-sirgod.html
Logged
I'm an InterN0T'er
Pages: [
1
]
Go Up
Print
« previous
next »
Jump to:
Please select a destination:
-----------------------------
EH-Net
-----------------------------
=> Calendar Of Events
===> ChicagoCon 2007
===> ChicagoCon 2008s
===> ChicagoCon 2008f
===> ChicagoCon 2009s
=> Ethical Hacktivism
=> News Items and General Discussion About EH-Net
===> Greetings
=> Special Events
-----------------------------
Ethical Hacking Discussions and Related Certifications
-----------------------------
=> General Certification
===> Networking
===> OS
===> Security
=> Compliance, Regulations & Standards
=> Control Systems
=> Cyber Warfare
=> Forensics
===> CCE / MCCE - (Master) Certified Computer Examiner
===> CHFI - Computer Hacking Forensic Investigator
===> EnCE - EnCase® Certified Examiner
===> GCFA - GIAC Certified Forensics Analyst
=> Hardware
=> Incident Response
===> CSIH - Computer Security Incident Handler
===> GCIH - GIAC Certified Incident Handler
=> Malware
===> Advisories
=> Mobile
=> Network Pen Testing
===> CEH - Certified Ethical Hacker
===> CPTC - Certified Penetration Testing Consultant
===> CPTE - Certified Penetration Testing Engineer
===> CSTA - Certified Security Testing Associate
===> eCPPT - eLearnSecurity Certified Professional Penetration Tester
===> ECSA - EC-Council Certified Security Analyst
===> GPEN - GIAC Certified Penetration Tester
===> OSCP - Offensive Security Certified Professional
=> Physical Security
=> Programming
=> Social Engineering
=> Web Applications
=> Wireless
===> CWNP Certs
===> GAWN - GIAC Assessing Wireless Networks
===> OSWP - Offensive Security Wireless Professional
=> Other
-----------------------------
Columns
-----------------------------
=> Editor-In-Chief
=> Andress
=> Gates
=> Haddix
=> Hadnagy
=> Heffner
=> Hoffman
=> Linn
=> RichM
=> Murray
=> J. Peltier
=> Weidman
=> Wilson
-----------------------------
Features
-----------------------------
=> /root
=> Book Reviews
=> Opinions
=> Skillz
===> Examples
===> May 06 - Star Hacks, Episode V: The Empire Hacks Back
===> July 06 - Hack Bill!
===> Sept 06 - Netcat in the Hat
===> Nov 06 - Hitch-Hackers Guide to the Galaxy
===> Dec 06 - A Christmas (Hacking) Story
===> Feb 07 - Charlottes Web Site
===> April 07 - Microsoft Office Space
===> June 07 - Serenity Hack
===> Oct 07 - Worst. Ethical. Hacker. Challenge. Ever.
===> Dec 07 - Frosty the Snow Crash
===> March 2008 - It Happened One Friday
===> Oct 2008 - Scooby Doo and the Crypto Caper
===> Dec 08 - Santa Claus Is Hacking to Town
===> Feb 2009 - Brady Bunch Boondoggle
===> July 2009 - Prison Break
===> October 2009 - SSHliders
===> December 2009 - Miracle on Thirty-Hack Street
===> December 2010 - The Nightmare Before Charlie Browns Christmas
-----------------------------
Resources
-----------------------------
=> Career Central
===> Looking For Work
===> Looking To Hire
=> Links to cool sites.
=> Mass Media
=> News from the Outside World
=> Tools
=> Tutorials
===> Tutorial Requests
Loading...
Exclusive Deal
SANSFIRE 2013
June 15 - 22
5% Off
w/ Code
:
EHN_5
SANS Deals 4 EH-Netters
5% OFF
Any
SANS Course
in Any Format!
Coupon Code:
EHN_5
Including
SANS Rocky Mountain 2013
&
SANS Boston 2013
Polls
Compared to this year, 2013 will be:
Great!
Better.
About the same.
Little worse.
FUBAR!
Recent Forum Topics
General Certification
: CPT Practical Submission
(0) by
z28power4u
OSCP - Offensive Security Certified Professional
: Class Scheduled 6/8 - Linux n00b
(5) by
MrTuxracer
Career Central
: Starter cert?
(0) by
Alert
Web Applications
: Nessus and Nikto
(4) by
Seen
Tutorials
: Need guidance
(7) by
impelse
Malware
: EICAR?
(2) by
SephStorm
Network Pen Testing
: Cracking salted MD5 hash
(4) by
n37sh@rk
CEH - Certified Ethical Hacker
: Passed my C|EH
(3) by
n37sh@rk
Mass Media
: EC-council hacked, irony at his best?
(0) by
j0rDy
Web Applications
: SQL Injection into an INSERT statement.
(6) by
eyenit0
Network Pen Testing
: Solution for sipXtapi INVITE Message CSeq Field Header Remote Overflow
(1) by
m0wgli
Web Applications
: dns
(2) by
H1t M0nk3y
Other
: BSides Boston
(0) by
3xban
Career Central
: InfoSec in Central, FL
(2) by
tturner
Web Applications
: Web vulnerability scanner
(4) by
H1t M0nk3y
EH-Net News Feeds
Latest Additions
Privacy Notice
for TDCC & All Properties
© 2013 The Ethical Hacker Network
Joomla!
is Free Software released under the GNU/GPL License.