Web Application Attack Types -Short Notes -Learning Day 2
Whenever people use to ask me about bug bounty , web application pentest i used to say them learn basics and then start up, The following post will give you some over view about whats all this buzz about ,how you need to test the application. I already explained in medium [ https://medium.com/@vignesh4303/infosec-story-web-application-attacks-noob-guide-1955369eae55 ]
The following were the attack types and will surely act as definite guide which will help up you to build yourself notes .
Although there were numerous notes for this attack type , the following will explain you the definite guide .first lets see the attack types :
1[+] Arbitrary[random] file access : Simple Accessing the sensitive files without authorization
2[+] Binary planting : Attacker places a binary file containing malicious code to load and execute it.
3[+] Blind SQL Injection : Database injection which just asks true or false questions and fetch the info.
4[+] Blind XPath Injection : The data stored in XML can be queried via XPath which is similar to SQL conceptually. It is also a query language and is used to locate specific elements in a XML document. Unlike sql which can be limited via resources , There is no limit for access control over here so user can exploit the misconfigured one .
5[+] Brute force attack : Straight forward , If 100 bullets fired at same target or 100 kisses continuously for you , or in simple words "gangbang"[dont google it ]
6[+] Buffer overflow attack : imagine you have place for eating 100 pizzas in stomach, if i forcefully make u eat the 101th pizza you will crash , Similarly exploiting the buffer and making it overflow at memory.
7[+] Cache Poisoning : Will write a detailed blog on this , as of now https://portswigger.net/research/practical-web-cache-poisoning
8[+] Cash Overflow : A Cash Overflow attack is a Denial of Service attack specifically aimed at exceeding the hosting costs for a cloud application, For simple example lets say application allows you to send unlimited sms from server, if you exploit it will cause loss of money.
9[+] Clickjacking : In simple words this bug used to load the certain page in certain window size, Usually low profile bug exploited by phishing and scammers
10[+] Command injection attacks : Allow you to execute certain commands in the website, Using application you will be allowed to execute commands.
11[+] Comment Injection Attack :
12[+] Content Security Policy : CSP policy will allow you to execute or load certain code within one end , If you bypass the code and make it execute it will be a bug.
13[+] Content Spoofing
14[+] Credential stuffing
15[+] Cross Frame Scripting
16[+] Cross Site History Manipulation (XSHM)
17[+] Cross Site Tracing
18[+] Cross-Site Request Forgery (CSRF)
19[+] Cross Site Port Attack (XSPA)
20[+] Cross-Site Scripting (XSS) : Executing malicious scripts in server and client side , Usually based on script inputs whichever gets executed .
21[+] Cross-User Defacement
22[+] Custom Special Character Injection
23[+] Denial of Service
24[+] Direct Dynamic Code Evaluation (‘Eval Injection’)
25[+] Execution After Redirect (EAR)
26[+] Exploitation of CORS
27[+] Forced browsing : Forcefully browsing content , Or force loading of certain resources without proper authorization.
28[+] Form action hijacking
29[+] Format string attack
30[+] Full Path Disclosure : Disclosing sensitive path in code,comments, directories.
31[+] Function Injection
32[+] Host Header injection : Will be usually performed at host header, eithr the header will be sent with malicous domain or null.
33[+] HTTP Response Splitting
34[+] HTTP verb tampering
35[+] HTML injection
36[+] LDAP injection : LDAP query injection where attacker form the malicious inputs which will fetch the system query, Usually works with login scenarios which has ldap as login authorization
37[+] Log Injection
38[+] Man-in-the-browser attack
39[+] Man-in-the-middle attack : Imagine you and your friend were passing sweets , suddenly a stranger comes and snatches your sweets .this is in short explanation, Technically the attacker will act like a proxy and steal up the resources whiehever sent to the server
40[+] Mobile code: invoking untrusted mobile code
41[+] Mobile code: non-final public field
42[+] Mobile code: object hijack
43[+] One-Click Attack
44[+] Parameter Delimiter
45[+] Page takeover
46[+] Path Traversal
47[+] Reflected DOM Injection
48[+] Regular expression Denial of Service – ReDoS
49[+] Repudiation Attack
50[+] Resource Injection
51[+] Server-Side Includes (SSI) Injection
52[+] Session fixation
53[+] Session hijacking attack
54[+] Session Prediction
55[+] Setting Manipulation
56[+] Special Element Injection
57[+] SMTP injection
58[+] SQL Injection
59[+] SSI injection
60[+] Traffic flood
61[+] Web Parameter Tampering
62[+] XPATH Injection
63[+] XSRF or SSRF
Huff ! breath taking isnt it , Will update all in coming days.Thanks.

Comments
Post a Comment