- Hands-On Bug Hunting for Penetration Testers
- Joseph Marshall
- 138字
- 2021-07-16 17:53:08
Attack Surface Reconnaisance – Strategies and the Value of Standardization
The Attack Surface of an application is, put succinctly, wherever data can enter or exit the app. Attack-surface analysis describes the methods used to describe the vulnerable parts of an application. There are formal processes, such as the Relative Attack Surface Quotient (RASQ) developed by Michael Howard and other researchers at Microsoft that counts a system's attack opportunities and indicates an app's general attackability. There are programmatic means available through scanners and manual methods, involving navigating a site directly, documenting weak points via screenshots and other notes. We'll talk about low- and high-tech methods you can use to focus your attention on profitable lines of attack, in addition to methods you can use to find hidden or leftover content not listed on the sitemap.
- 攻守道:企業(yè)數(shù)字業(yè)務(wù)安全風(fēng)險與防范
- 網(wǎng)絡(luò)安全與管理
- Securing Blockchain Networks like Ethereum and Hyperledger Fabric
- Metasploit Penetration Testing Cookbook(Second Edition)
- 網(wǎng)絡(luò)安全保障能力研究
- Wireshark 2 Quick Start Guide
- 黑客攻防入門秘笈
- 黑客攻防與無線安全從新手到高手(超值版)
- Kali Linux Wireless Penetration Testing Cookbook
- 模糊測試:強(qiáng)制發(fā)掘安全漏洞的利器
- Instant Java Password and Authentication Security
- 網(wǎng)絡(luò)安全與攻防入門很輕松(實戰(zhàn)超值版)
- 網(wǎng)絡(luò)服務(wù)安全與監(jiān)控
- 白話零信任
- 網(wǎng)絡(luò)空間安全:拒絕服務(wù)攻擊檢測與防御