Penetration testing

Manual Web Application Penetration Testing – Suffix & Prefix in Fuzzing

Introduction In this series of articles, last time we talked about fuzzing and various SQL statement special characters which can be used in fuzzing a web ap

Manually Web Application Penetration Testing: Fuzzing

Introduction When we test a web application, we do not test a single page, but a lot of pages of a single web application. Each page may have more than one v

Web Services Penetration Testing, Part 6: Fuzzing Parameters with Burp

In the previous article we discussed in what cases we might face challenges performing manual web services penetration testing and how SoapUI will help in th

Adobe CQ Pentesting Guide – Part 1

This post deals with the step-by-step security testing guidelines for Adobe CQ installation. Adobe CQ is Adobe's new Web Experience Management software portf

Android Application Penetration Testing: Setting up, Certificate Installation and GoatDroid Installation

To begin with mobile application penetration testing on the Android platform, we have multiple tools available that can be easily downloaded and installed to

Learning how to pentest VPNs with VulnVPN

VulnVPN has been created by the author of http://www.rebootuser.com/ and I must say that it is a very good effort. The goal is to gain root access to a VPN s

Web Services Penetration Testing Part 4: Manual Testing with SOA Client

In the previous article, we discussed the automated tools available for testing web services, how to automate web services penetration testing using differe

Web Services Penetration Testing Part 3: Automation with AppScan and Webinspect

In the previous article, we discussed the importance of tools in penetration testing, how automation helps in reducing time and effort, and how to automate

Penetration testing of an FTP service

In this article we are going to learn how to configure ProFTPD service in a CentOS machine. After that we will conduct penetration testing to evaluate the se

Pentesting distributions and installer kits for your Raspberry Pi

Raspberry Pi for pwning and penetration testing? Of course! Why not? As an introduction, Raspberry Pi is an ARM GNU / Linux box or a credit card size mini co