![]() |
|
Where can I learn about website hacking? - Printable Version +- Sinisterly (https://sinister.li) +-- Forum: Hacking (https://sinister.li/Forum-Hacking) +--- Forum: Website & Server Hacking (https://sinister.li/Forum-Website-Server-Hacking) +--- Thread: Where can I learn about website hacking? (/Thread-Where-can-I-learn-about-website-hacking) |
Where can I learn about website hacking? - Frenzied - 05-21-2016 I've recently got in to SQL injection and it's fun and all, but very easy and very few websites still have problems in their SQL. I'd like to learn more advanced stuff, eg: Hacking websites with asp or forums, I have no idea, I'd love to become white-hat one day and help people, Thanks! :=) RE: Where can I learn about website hacking? - Dozy Van - 05-21-2016 SQL injection has really fallin down the list. There are still a lot of websites that are vlun to it but you have to do a blind SQL injection a lot of the time and thats not quite as easy as you don't get prompts back. I think currently last I looked at the stats cross site scripting is the most common form of weakness in websites today. That said using sqlmap with a particular google serch function in kali linux will still walk you into a lot of websites when you know how to use it though. As I only come at things from the ethical hacking point of view. If you really want to learn more I suggest you learn BurpSuit, boot up a kali linux VM. Set up Tomcat and web goat: https://www.owasp.org/index.php/Category:OWASP_WebGoat_Project When you boot up BurpSuit you will need to change the ports it uses as it and tomcat try and use the same ports and nothing will work. Set up burpSuit with the addon FoxyProxy https://nvisium.com/blog/2014/01/10/setting-up-burpsuite-with-firefox-and/ BurpSuit is amazingly powerfull and I use it quite a lot for what I do. You only get the free version on Kali Linux but thats fine. I think I use BurpSuit, Nessus and metasploit more than any other tool's if I am honest. RE: Where can I learn about website hacking? - Frenzied - 05-21-2016 (05-21-2016, 12:45 PM)Dozy Van Wrote: SQL injection has really fallin down the list. There are still a lot of websites that are vlun to it but you have to do a blind SQL injection a lot of the time and thats not quite as easy as you don't get prompts back. I think currently last I looked at the stats cross site scripting is the most common form of weakness in websites today. That said using sqlmap with a particular google serch function in kali linux will still walk you into a lot of websites when you know how to use it though. Thanks man, I'll leave my kali linux downloading today and I'll try out everything you said, so what does this BurpSuit do exactly? and what type of websites do you use it on? I've never actually learned about pentests and stuff so I'm not that familiar on those topics c: RE: Where can I learn about website hacking? - Dozy Van - 05-21-2016 It has a lot in its package I normally just use it as an intercepting Proxy. This lets me inspect and modify traffic between me and the website or game or whatever the application it is that I am attacking. So for like those flash games. When you go to submit your score you can actually intercept the packet that has your score and change it from 1,000 to 1,000,000,000,000,000,000 or to whatever the maximum value is. but this is only just 1 of many features. https://portswigger.net/burp/ edit: I did find this https://alexandervoidstar.wordpress.com/2015/06/21/how-to-install-and-configure-webgoat-5-3-with-iceweasel-and-burpsuite-on-kali-linux/ Remember to use foxyproxy as that means you can toggle on and off burpsuit as you please. Also remember to change burpsuits port. Note: When installing kali Linux it would sometimes the installer would break for me unless I gave it like 50/60+G's of space to use. Idk why but just an fyi if your having issues with the installer. RE: Where can I learn about website hacking? - meow - 05-21-2016 Something you should do in this era is research JSON/REST/Ajax APIs and their security. The use of those APIs has been growing rapidly within the cyber industry, and new vulnerabilities are arising thanks to them. Also, while Burp Suite is an excellent tool for this^ kind of stuff, it's important to have a strong grasp of how HTTP works before jumping to tools so that you're not just blindly using something that you have no clue about. |