How To Do Web Penetration Testing?

Let’s learn how To Do Web Penetration Testing. The most accurate or helpful solution is served by Server Fault.

There are ten answers to this question.

Best solution

Looking for a good web penetration testing client

I'm implementing mod_security on an apache server. In order to test the effectiveness of the protection, I am looking for a client that can generate a set of predefined malicious HTTP requests. I will test the requests with and without mod_security enabled and based on the logs see what percentage of malicious requests has been blocked. Do you know any good tools to generate a set of predefined malicious HTTP requests?

Answer:

There's several free/open source options out there. A close friend of mine who's a Web applications...

Read more

user64204 at Server Fault Mark as irrelevant Undo

Other solutions

Any good books on web penetration testing?

Any good books on web penetration testing? I'm a web developer and consultant, and I often deal with web application security. Everything I know about penetration testing I've learned in a pretty ad hoc manner, and I think it's time to give myself a...

Answer:

The OWASP testing guide is a good set of industry standards.

Read more

jacobian at Ask.Metafilter.Com Mark as irrelevant Undo

Penetration testing reported zero vulnerabilities. Does this mean my web app is secure?

I've spent many hours on whitebox testing to make sure my code was safe. From a theoretical standpoint, the code SHOULD be safe. I then used several widely known testing tools (including one that cost $3500) to test for SQL injections, cross site scripting...

Answer:

The question is, "Do you know how to use the testing tools?" A tho...

Read more

Benjamin Teo at Quora Mark as irrelevant Undo

What are the metrics that has to be considered while designing Benchmarks for Web Application penetration testing tools? What benchmarks for cloud based tools?

I have a job to evaluate best cloud based vulnerability assessment and PT tools like Enprobe.io , http://Risk.io. Also best standalone tools like IBM App scanner, Acunetix etc. Can anyone help with required link if there is an existing benchmark or how...

Answer:

I have done a big research in regards to benchmarking tools for web application used in penetration...

Read more

Shritam Bhowmick at Quora Mark as irrelevant Undo

Answer:

Nasrumminallah Zeeshan http://www.twitter.com/Nz_Hackti... YES, he do needs Penetration Testing. Having...

Read more

Nasrumminallah Zeeshan at Quora Mark as irrelevant Undo

What can I expect for the cost of hiring a quality third party penetration testing firm?

I'm looking for a third party penetration testing option for current and future web applications, but I have no context on the pricing expectation vs quality.  Is there any reliable source for review pricing information?

Answer:

Hi Manish, First I would like to say, you have asked a question that would be a concern of many readers...

Read more

Ankit Shankar Giri at Quora Mark as irrelevant Undo

What's the best way for a web application developer to transition to a career as a Penetration Tester?

I recently graduated from Dev Bootcamp, where I learned to build web applications using Ruby, Rails and Javascript.  However, I'm considering pivoting to a career in penetration testing and ethical hacking, and I'm wondering where I would need to start...

Answer:

Well, to be very straight forward to the point I would like to mention that it's not mendatory to learn...

Read more

Palashh Baraniya at Quora Mark as irrelevant Undo

How to choose client side technologies for a new web project.

Why shouldn't we use Flash? Why should we use AJAX (DHTML/Javascript)? Should we support IE6? I'm wrestling with these questions for a new web product, and I'd like insight from others. This is for a consumer oriented web app (as opposed to B2B). A richly...

Answer:

My company does a tremendous amount of web software development for other companies -- we use both flex...

Read more

Good Brain at Ask.Metafilter.Com Mark as irrelevant Undo

What are open source tools for web security auditing?

List of open source tools for web security penetration testing/auditing.

Answer:

Web security auditing will require a lot of tools your arsenal. So, the following are a must if we talk...

Read more

Ankit Shankar Giri at Quora Mark as irrelevant Undo

What are your favorite web testing tools?

Web developers - what tools do you use to test your sites? I've been tasked with putting together a list of web testing tools. Since that's a really useful question in general, I thought I would get the hive mind's input. What tools do you use for website...

Answer:

I've used selenium for web application unit testing.

Read more

fremen at Ask.Metafilter.Com Mark as irrelevant Undo

Related Q & A:

Just Added Q & A:

Find solution

For every problem there is a solution! Proved by Solucija.

  • Got an issue and looking for advice?

  • Ask Solucija to search every corner of the Web for help.

  • Get workable solutions and helpful tips in a moment.

Just ask Solucija about an issue you face and immediately get a list of ready solutions, answers and tips from other Internet users. We always provide the most suitable and complete answer to your question at the top, along with a few good alternatives below.