14 - Hacking Web Apps
Module 14: Hacking Web Applications
User Enumeration and Brute Force Attack
WP user enumeration
WP password bruteforce
RCE
Perform a Brute-force Attack using Burp Suite
Exploit Parameter Tampering and XSS Vulnerabilities in Web Applications
Enumerate and Hack a Web Application using WPScan and Metasploit
Exploit a Remote Command Execution Vulnerability to Compromise a Target Web Server (DVWA low level security)
File Upload Vulnerability β All Levels DVWA
Payload Creation
Low Level Exploitation
Medium Level Exploitation
High Level Exploitation
Cross-Site Request Forgery (CSRF)
Additional Resources
Web Scanners
YT videos
Last updated