Web Application Pentest Lab setup Using Docker
In the world of cybersecurity, penetration testing and vulnerability assessment are crucial steps in identifying and mitigating potential security threats. With the increasing number of web...
View ArticleExploiting Race Condition using Turbo Intruder
In web security, a race condition refers to a scenario where the behaviour of a web application is influenced by the sequence or timing of events, potentially leading to unintended security...
View ArticleBurpsuite for Pentester: Autorize
In order to protect online assets, web application security testing is an essential element of safeguarding them. Burp Suite has been a leader in this area for many years and it’s still being used by...
View ArticleBurpsuite for Pentester: Logger++
In this article, we’ll learn about a powerful Burp Extension cool tool called “Burp Logger++”. It is like a super detective for websites, always on the lookout for any hidden problems. It is an extra...
View ArticleA Detailed Guide on httpx
Introduction httpx is a fast web application reconnaissance tool coded in go by www.projectidscovery.io. With a plethora of multiple modules effective in manipulating HTTP requests and filtering out...
View ArticleBurp Suite for Pentester: Repeater
Today, in this article, we’ll focus on the Repeater and its options featured by the Burp Suite Professional Version, which will help any Pentester to send the request inside the burp and observe its...
View ArticleBurp Suite for Pentester: Burp’s Project Management
A Burp project is basically a file over where we store and organize our work for a specific test. But what if you’re working on a particular application and you might take days to test that? Today, in...
View ArticleBurp Suite for Pentester: Software Vulnerability Scanner & Retire.js
Not only the fronted we see or the backend we don’t, are responsible to make an application be vulnerable. A dynamic web-application carries a lot within itself, whether it’s about JavaScript...
View ArticleBurp Suite for Pentester: Active Scan++
Using Burp Suite as an automated scanner? Wondering right, even some pentesters do not prefer it, due to the fewer issues or the vulnerabilities it carries within. But what, if the burp scanner itself...
View ArticleBurp Suite for Pentester: Turbo Intruder
Is fuzzing your favourite attack type, but you didn’t enjoy it due to the low speed and high memory usage when you work over with some big dictionaries? So, today over with this article, we’ll explore...
View ArticleBurp Suite for Pentester: Burp Sequencer
Whenever we log into an application, the server issues a Session ID or a token, and all over from the internet we hear that the session ID we get is unique, but what, if we could guess the next unique...
View ArticleBurp Suite For Pentester: HackBar
Isn’t it a bit time consuming and a boring task to insert a new payload manually every time for a specific vulnerability and check for its response? So, today in this article we’ll explore one of the...
View ArticleBurp Suite for Pentester: Burp Collaborator
A number of vulnerabilities exist over the web, but the majority of them are not triggered directly as they do not reproduce any specific output or an error. So, is the output or the error is the only...
View ArticleBurp Suite for Pentester: Web Scanner & Crawler
You might be using a number of different tools in order to test a web-application, majorly to detect the hidden web-pages and directories or to get a rough idea about where the low-hanging fruits or...
View ArticleComprehensive Guide on XXE Injection
XML is a markup language that is commonly used in web development. It is used for storing and transporting data. So, today in this article, we will learn how an attacker can use this vulnerability to...
View ArticleBurp Suite for Pentester – Fuzzing with Intruder (Part 3)
After reading both of our previous articles, you might be wondering, “What about the other features or sections that Burpsuite’s Intruder offers us?” or “How can we use the other payload options rather...
View ArticleBurp Suite for Pentester – Fuzzing with Intruder (Part 2)
Over in the previous article, we learned about what fuzzing is and how the burpsuite helps us to fuzz a web-application, along with all these things we had even explored some great fuzzing payload...
View ArticleBurp Suite for Pentester – Fuzzing via Intruder Tab
Whether it’s guessing up a login credential or opting a valid payload for a specific vulnerability, both of these things are time-consuming and require a number of permutation and combination to built...
View ArticleBurp Suite for Pentester – XSS Validator
You might have used a number of online tools to detect XSS vulnerabilities and a few to validate them and thereby, at last, with all the generated outcome you try to exploit the injection point...
View ArticleBurp Suite for Pentester – Configuring Proxy
Burp Suite, you might have heard about this great tool and even used it in a number of times in your bug hunting or the penetration testing projects. Though, after writing several articles on...
View Article