Saturday, November 2, 2019

Web applications pen testing

https://www.veracode.com/security/arp-spoofing ( web application flaws and vulnerabilities tutorials)
https://www.apriorit.com/dev-blog/622-qa-web-application-pen-testing-owasp-checklist
https://www.hacker101.com/ (free video lessons on ethical hacking and bug bounty )
https://hackademy.aetherlab.net/p/burp-suite ( for manual testing with Burp suite for free video lecture)
https://www.guru99.com/complete-web-application-testing-checklist.html
https://www.instart.com/blog/4-common-web-application-security-attacks-and-what-you-can-do-prevent-them
https://www.blackhat.com/trainings/ (Training of Black hat)
https://www.whitehatsec.com/glossary/ (various vulnerable attacks and analysis)
https://portswigger.net/blog/null-byte-attacks-are-alive-and-well
https://www.veracode.com/blog/secure-development/top-five-web-application-authentication-vulnerabilities-we-find
https://www.exploit-db.com/docs/english/44319-web-application-security-testing.pdf


Interview questions -Pen Testing
https://www.janbasktraining.com/blog/security-testing-interview-questions/ (15 questions and answers)
https://resources.infosecinstitute.com/category/certifications-training/pentesting-certifications/pentesting-interview-questions/ (10 Common Interview Questions For Penetration Testers )
https://resources.infosecinstitute.com/category/certifications-training/pentesting-certifications/pentesting-interview-questions/
https://www.wisdomjobs.com/e-university/malware-interview-questions.html     (250+ MALWARE INTERVIEW QUESTIONS & ANSWERS)
https://www.wisdomjobs.com/e-university/malware-interview-questions.html (50+ interview questions on Cyber security)
https://www.edureka.co/blog/interview-questions/cybersecurity-interview-questions/
APPROACHES, TOOLS AND TECHNIQUES FOR SECURITY TESTING
https://www.3pillarglobal.com/insights/approaches-tools-techniques-for-security-testing

Attacking Types, Methadology, Counter measures
https://www.greycampus.com/opencampus/ethical-hacking/web-server-and-its-types-of-attacks
(Web Server and its Types of Attacks)

Tips for securing Web-based applications
https://searchsecurity.techtarget.com/tip/Tips-for-securing-Web-based-applications?bucket=ETA
webpage programming from KHAN Academy

https://www.khanacademy.org/computing 

Thursday, October 31, 2019

web applications pen Testing and samurai framework for web applications testing

https://www.tutorialspoint.com/penetration_testing/penetration_testing_quick_guide.htm (step by step procedure on manual testing and automated pen testing)
 Penetration testers knowledge and expertise: 
Black hat attack methodologies (e.g., remote access attacks, SQL injection)
Internal and external testing (i.e., perspective of someone within the network, perspective of hacker over Internet)
Web front-end technologies (e.g.,Javascript, HTML)
Web application programming languages (e.g., Python, PHP)
Web APIs (e.g., restful, SOAP)
Network technologies (e.g, firewalls, IDS)
Networking protocols (e.g., TCP/UDP, SSL)
Operating systems (e.g., Linux, Windows)
Scripting languages (e.g., python, pearl)
Testing tools (e.g., Nessus, Metasploit)
In short, penetration testers provide a deep look into the data security of an organization.
https://www.netsparker.com/blog/web-security/getting-started-web-application-security/
https://searchsecurity.techtarget.com/tip/5-step-checklist-for-web-application-security-testing
https://www.tutorialspoint.com/penetration_testing/penetration_testing_quick_guide.htm
https://www.guru99.com/web-application-testing.html
http://www.internet-computer-security.com/VPN-Guide/SSL-VPN.html
https://sectools.org/tool/samurai/
https://www.apriorit.com/dev-blog/622-qa-web-application-pen-testing-owasp-checklist

What are the Skill-Sets of Ethical Hackers?
Expert ethical hackers have the following skill-sets to hack the system ethically

What do Ethical Hackers do?
Ethical hackers (while performing penetration testing) basically try to find the answers to the following questions −


Moreover, an ethical hacker is required to address adequately the vulnerabilities and risks, which he found to exist in the target system(s). He needs to explain and suggest the avoidance procedures. Finally, prepare a final report of his all ethical activities that he did and observed while performing penetration testing.

SSL VPN (Secure Socket Layer VPN)