Webapp Pentesting Archives - GBHackers Security | #1 Globally Trusted Cyber Security News Platform https://gbhackers.com/category/webapp/ GBhackers Offering Exclusive Cyber Security News Coverage, New Research papers & Technology Updates. Tue, 03 Sep 2024 07:37:57 +0000 en-US hourly 1 https://wordpress.org/?v=6.6.2 https://gbhackers.com/wp-content/uploads/2024/09/cropped-gbh-32x32.png Webapp Pentesting Archives - GBHackers Security | #1 Globally Trusted Cyber Security News Platform https://gbhackers.com/category/webapp/ 32 32 Web Server Penetration Testing Checklist – 2024 https://gbhackers.com/web-server-penetration-testing-checklist/ https://gbhackers.com/web-server-penetration-testing-checklist/#respond Sat, 13 Jan 2024 13:09:33 +0000 https://gbhackers.com/?p=3386 Web server pentesting is performed under three significant categories: identity, analysis, and reporting vulnerabilities such as authentication weaknesses, configuration errors, and protocol relationship vulnerabilities.  1.  “Conduct a series of methodical and repeatable tests ” is the best way to test the webserver to work through all of the different application vulnerabilities. 2. “Collecting as Much Information” about […]

The post Web Server Penetration Testing Checklist – 2024 appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.

The post Web Server Penetration Testing Checklist – 2024 appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.

]]>
https://gbhackers.com/web-server-penetration-testing-checklist/feed/ 0
ReconAIzer: OpenAI-based Extension for Burp Suite https://gbhackers.com/reconaizer-burp-extension/ https://gbhackers.com/reconaizer-burp-extension/#respond Wed, 13 Sep 2023 17:03:50 +0000 https://gbhackers.com/?p=73604 Burp Suite, the renowned Bug Bounty Hunting and Web Application Penetration Testing tool, has been improvised with many extensions over the years. Many of Burp’s Extensions have been used by Bug Bounty Hunters and Security Researchers for various purposes. It has been nearly a year since the introduction of ChatGPT by OpenAI. Several sectors have […]

The post ReconAIzer: OpenAI-based Extension for Burp Suite appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.

The post ReconAIzer: OpenAI-based Extension for Burp Suite appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.

]]>
https://gbhackers.com/reconaizer-burp-extension/feed/ 0
HackerOne Lays off 12% of Its Employees as a One-Time Event  https://gbhackers.com/hackerone-lays-off/ https://gbhackers.com/hackerone-lays-off/#respond Thu, 03 Aug 2023 14:58:20 +0000 https://gbhackers.com/?p=70903 HackerOne is a renowned cybersecurity company that offers bounty and penetration testing platforms to ethical hackers for the following activities:- HackerOne is a San Francisco-based startup, and at the moment, it boasts more than 450 employees globally. However, HackerOne CEO Marten Mickos recently announced that the company decided to lay off 12% of its employees […]

The post HackerOne Lays off 12% of Its Employees as a One-Time Event  appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.

The post HackerOne Lays off 12% of Its Employees as a One-Time Event  appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.

]]>
https://gbhackers.com/hackerone-lays-off/feed/ 0
Web Application Pentesting – Manual SQL Injection With Error Based String Method https://gbhackers.com/manual-sql-injection/ https://gbhackers.com/manual-sql-injection/#respond Tue, 01 Aug 2023 17:06:00 +0000 https://gbhackers.com/?p=13077 SQL injection is the code injection technique to gain access to the database(MySQL, MSSQL, Oracle etc). Owasp 2018 Release still describes this injection as an A1 or Level 1 injection which is the most dangerous attack of all time. SANS Top 25(Most Dangerous Software Errors) describes SQL injection as Improper Neutralization of Special Elements used in an SQL Command (‘SQL […]

The post Web Application Pentesting – Manual SQL Injection With Error Based String Method appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.

The post Web Application Pentesting – Manual SQL Injection With Error Based String Method appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.

]]>
https://gbhackers.com/manual-sql-injection/feed/ 0
Burp Suite 2023.8 Released – What’s New! https://gbhackers.com/burp-suite-2023-8/ https://gbhackers.com/burp-suite-2023-8/#respond Tue, 01 Aug 2023 16:12:31 +0000 https://gbhackers.com/?p=70801 The updated Burp suite scanner has new add-on features and bug fixes that enhance the scanning process’s overall performance. Burp Suite is an integrated platform/graphical tool for performing security testing of web applications. On 27 July 2023, Portswigger released all improved versions of Burpsuite, including the reuse of HTTP/1, customizable SNI values, browser updates, and […]

The post Burp Suite 2023.8 Released – What’s New! appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.

The post Burp Suite 2023.8 Released – What’s New! appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.

]]>
https://gbhackers.com/burp-suite-2023-8/feed/ 0
8 Best Web Security and Hacking Software for Security Professionals in 2024 https://gbhackers.com/best-hacking-software/ https://gbhackers.com/best-hacking-software/#respond Thu, 20 Jul 2023 02:15:00 +0000 https://gbhackers.com/?p=33337 Hacking software is not only used by hackers for criminal activities but it’s equally used by white hat hackers and security professionals to identify a vulnerability in a network or an endpoint. There are several hacking software available on the internet, including commercial and non-commercial offerings. It’s always good to test your network security from […]

The post 8 Best Web Security and Hacking Software for Security Professionals in 2024 appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.

The post 8 Best Web Security and Hacking Software for Security Professionals in 2024 appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.

]]>
https://gbhackers.com/best-hacking-software/feed/ 0
Web Application Attacks – Types, Impact & Mitigation – Part-2 https://gbhackers.com/web-application-attacks-part-2/ https://gbhackers.com/web-application-attacks-part-2/#respond Mon, 10 Jul 2023 05:10:00 +0000 https://gbhackers.com/?p=44535 With this article, we list some of the common Web Application Attacks part-2, impacts, and possible mitigation. In part -2 we are covering the following attacks. Session Fixation The session fixation attack is a class of Session Hijacking, which steals the established session between the client and the Web Server after the user logs in. Instead, the Session Fixation attack fixes an established session on […]

The post Web Application Attacks – Types, Impact & Mitigation – Part-2 appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.

The post Web Application Attacks – Types, Impact & Mitigation – Part-2 appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.

]]>
https://gbhackers.com/web-application-attacks-part-2/feed/ 0
Burp Suite New GraphQL API to Detect Hidden Endpoints https://gbhackers.com/burp-suite-graphql-api/ https://gbhackers.com/burp-suite-graphql-api/#respond Wed, 05 Jul 2023 08:24:35 +0000 https://gbhackers.com/?p=68297 The Burp Scanner’s new GraphQL capabilities allow it to recognize known endpoints, locate hidden endpoints, determine whether introspection or recommendations are enabled, and report when an endpoint fails to validate the content type. Portswigger, the firm behind the renowned web application security testing tool Burp Suite, has announced that Burp Scanner’s new GraphQL checks will […]

The post Burp Suite New GraphQL API to Detect Hidden Endpoints appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.

The post Burp Suite New GraphQL API to Detect Hidden Endpoints appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.

]]>
https://gbhackers.com/burp-suite-graphql-api/feed/ 0
Scanning for OWASP Top 10 With w3af – An Open-source Web Application Security Scanner https://gbhackers.com/scanning-owasp-top-10/ https://gbhackers.com/scanning-owasp-top-10/#comments Sat, 01 Jul 2023 03:06:00 +0000 https://gbhackers.com/?p=9363 w3af is an open-source web application security scanner (OWASP Top 10) that enables developers and penetration testers to distinguish and exploit vulnerabilities in their web applications, especially OWASP Top 10 Vulnerabilities. This tool also provides GUI framework but sadly most of the time GUI mode hangs up, most recommended is to work with w3afconsole. It […]

The post Scanning for OWASP Top 10 With w3af – An Open-source Web Application Security Scanner appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.

The post Scanning for OWASP Top 10 With w3af – An Open-source Web Application Security Scanner appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.

]]>
https://gbhackers.com/scanning-owasp-top-10/feed/ 1
Web Application Pentesting with Manual SQL Injection – Integer Based https://gbhackers.com/perform-manual-sql-injection/ https://gbhackers.com/perform-manual-sql-injection/#respond Mon, 26 Jun 2023 11:55:00 +0000 https://gbhackers.com/?p=13572 Today we will perform manual SQL injection with an integer-based method for the MySQL database. I hope the last article on error-based string injection is useful to everyone, especially beginners. Now I will quickly drive into yet another writing for SQL injection with the integer-based method. SQL Injection ONLINE LAB: STEP 1: Breaking the Query […]

The post Web Application Pentesting with Manual SQL Injection – Integer Based appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.

The post Web Application Pentesting with Manual SQL Injection – Integer Based appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.

]]>
https://gbhackers.com/perform-manual-sql-injection/feed/ 0