Please enable JavaScript.
Coggle requires JavaScript to display documents.
VAPT (Web Application (Cross Site scripting (XSS) (Stored Cross-site…
VAPT
Web Application
Check for Open Directories
Check for open Ports
Nmap
https://tools.kali.org/information-gathering/nmap
Zenmap
https://nmap.org/zenmap/
Wordress site Vulnerablity
WPScan
https://wpscan.org/
Web application tester
Owasp-zap
https://www.owasp.org/index.php/OWASP_Zed_Attack_Proxy_Project
SQL Injection
https://www.veracode.com/security/sql-injection
https://sqlzoo.net/hack/
Click jacking
Broken Authentication and Session Management
Insecure Direct Object References
Cross site Request Forgery
Insecure Cryptographic Storage
Failure to restrict URL Access
Insufficient Transport Layer Protection
Unvalidated Redirects and Forwards
Cross Site scripting (XSS)
Stored Cross-site Scripting Vulnerability
https://www.netsparker.com/blog/web-security/cross-site-scripting-xss/
Reflected Cross-site Scripting (XSS) Vulnerability
DOM Based Cross-site Scripting Vulnerability
https://www.netsparker.com/blog/web-security/dom-based-cross-site-scripting-vulnerability/
Tools to be explored
Metasploit
Websploit
OWASP Tools
Nessus
OpenVAS
https://securitytrails.com/blog/top-15-ethical-hacking-tools-used-by-infosec-professionalshacking
https://github.com/swisskyrepo/PayloadsAllTheThings
Wi-Fi
Wifi Password Cracking
Brute force Method
Aircrack-ng Method
https://medium.com/@brannondorsey/crack-wpa-wpa2-wi-fi-routers-with-aircrack-ng-and-hashcat-a5a5d3ffea46
https://www.wikihow.com/Hack-WPA/WPA2-Wi-Fi-with-Kali-Linux
Phishing Method
Fluxion
Method
https://null-byte.wonderhowto.com/forum/fluxion-cracking-wifi-without-bruteforce-wordlist-kali-linux-2017-1-full-guide-0178727/
Ghost Phisher
https://tools.kali.org/information-gathering/ghost-phisher
Mask Attack
https://www.4armed.com/blog/perform-mask-attack-hashcat/
https://tools.kali.org/password-attacks/maskprocessor
Hybrid Attack
https://hashcat.net/wiki/doku.php?id=hybrid_attack
Check for shared folders inside a network
https://superuser.com/questions/856617/how-do-i-recursively-download-a-directory-using-smbclient
https://askubuntu.com/questions/198501/list-of-all-shared-folders
Check for access to camera
Denial of Service (DOS attack)
SSL Strip (ARP Spoofing)
References
https://www.tutorialspoint.com/security_testing/security_testing_quick_guide.htm
https://www.tutorialspoint.com/penetration_testing/penetration_testing_report_writing.htm