官术网_书友最值得收藏!

Manual testing

This is the stage where the tester's presence of mind helps him find various vulnerabilities in the application. In this phase, the attacker manually tests for flaws by fuzzing different input fields and checking the application response. There are times where a scanner will not be able to find certain vulnerabilities and user intervention is much needed, and this is where manual testing prospers. Certain vulnerabilities tend to be missed out by automated scanners, such as :

  • Various business logic flaws
  • Second-order SQL injection 
  • Pentesting cryptographic parameters
  • Privilege escalation
  • Sensitive information disclosures
主站蜘蛛池模板: 罗田县| 旬邑县| 福建省| 石首市| 绥化市| 湟源县| 乳源| 天镇县| 中西区| 神农架林区| 鄂伦春自治旗| 邢台市| 葫芦岛市| 隆安县| 怀仁县| 台前县| 吉木乃县| 邵东县| 嘉禾县| 乌鲁木齐县| 岱山县| 扎兰屯市| 岱山县| 郑州市| 沾益县| 五家渠市| 万全县| 清河县| 兰州市| 布拖县| 古蔺县| 贵定县| 阳山县| 邵东县| 闽侯县| 栾城县| 广汉市| 九江县| 阿瓦提县| 涪陵区| 华安县|