VAPT
A working methodology for vulnerability assessment and penetration testing: scope, phases, reporting, and a running list of study resources.
On this page
Vulnerability Assessment and Penetration Testing
- If it's for a web app you need to systematically work through the OWASP WSTG to make sure you don't miss anything.
- Use CVSS3.1 to calculate severity, it’s industry standard
- http://www.pentest-standard.org/index.php/Main_Page
How to handle Network VAPT
- Scope
- List of Network Devices Routers, Laptop, Desktop, Firewall, IDS, Access point, IPS
- Network Architecture Diagram
- Type of Testing:
- VA (with/without Credentials)
- VAPT
- Kick-off Meeting with client
- Number of locations
- Number of VLAN's
- List of Public IP
- List of Internal IP
- VPN Access/Remote Desktop
- I5, 8g, SSD, Good Internet
- Phase 1 Testing
- Testing Schedule
- Nessus, Nmap, Wireshark/Metasploit(PT)
- Report writing
- Patching
- Report Discussion
- Retesting
Finish
-
- It was about simple N map scan followed by dir buster and then getting reverse outbound connection using Metasploit to get access. Later, he got root privilege and got shadow and passwd files then he tried cracking it using password crackers.
-
- Six Step Process
- Pre engagement
- Recon
- Vulnerability Assessment
- Exploitation
- Post Exploitation
- Reporting
- Six Step Process
-
- How to Handle VAPT project?
https://tryhackme.com/hacktivities https://academy.tcm-sec.com/courses
Reverse Engineering
- https://yurichev.org/RE_start/
- Reverse Engineering for Everyone
- Binary Ninjas in Training
- GitHub Resources
- Goldbot.org
- Getting Started with Reverse Engineering
API Security
Resources
Books
- Hacking APIs
Broken Object Level Authorization
also known as IDOR
Types of Access Control
-
Role based
-
Discretionary(Cloud Share)
-
Attribute based(Rare in webapps)
-
Mess with cookies
-
Access something without login
-
Access other users resources
-
Admin function as regular user