Web Application Attack Types -Short Notes -Learning Day 2

 Whenever people use to ask me about bug bounty , web application pentest i used to say them learn basics and then start up, The following post will give you some over view about whats all this buzz about ,how you need to test the application. I already explained in medium [ https://medium.com/@vignesh4303/infosec-story-web-application-attacks-noob-guide-1955369eae55 ]

The following were the attack types and will surely act as definite guide which will help up you to build yourself notes .

Although there were numerous notes for this attack type , the following will explain you the definite guide .first lets see the attack types :

1[+] Arbitrary[random] file access : Simple Accessing the sensitive files without authorization

2[+] Binary planting : Attacker places a binary file containing malicious code to load and execute it.

3[+] Blind SQL Injection : Database injection which just asks true or false questions and fetch the info.

4[+] Blind XPath Injection : The data stored in XML can be queried via XPath which is similar to SQL conceptually. It is also a query language and is used to locate specific elements in a XML document. Unlike sql which can be limited via resources , There is no limit for access control over here so user can exploit the misconfigured one .

5[+] Brute force attack : Straight forward , If 100 bullets fired at same target or 100 kisses continuously for you , or in simple words "gangbang"[dont google it ]

6[+] Buffer overflow attack : imagine you have place for eating 100 pizzas in stomach, if i forcefully make u eat the 101th pizza you will crash , Similarly exploiting the buffer and making it overflow at memory.

7[+] Cache Poisoning : Will write a detailed blog on this , as of now https://portswigger.net/research/practical-web-cache-poisoning

8[+] Cash Overflow : A Cash Overflow attack is a Denial of Service attack specifically aimed at exceeding the hosting costs for a cloud application, For simple example lets say application allows you to send unlimited sms from server, if you exploit it will cause loss of money.

9[+] Clickjacking : In simple words this bug used to load the certain page in certain window size, Usually low profile bug exploited by phishing and scammers

10[+] Command injection attacks : Allow you to execute certain commands in the website, Using application you will be allowed to execute commands.

11[+] Comment Injection Attack : 

12[+] Content Security Policy : CSP policy will allow you to execute or load certain code within one end , If you bypass the code and make it execute it will be a bug.

13[+] Content Spoofing

14[+] Credential stuffing

15[+] Cross Frame Scripting

16[+] Cross Site History Manipulation (XSHM)

17[+] Cross Site Tracing

18[+] Cross-Site Request Forgery (CSRF)

19[+] Cross Site Port Attack (XSPA)

20[+] Cross-Site Scripting (XSS) : Executing malicious scripts in server and client side , Usually based on script inputs whichever gets executed .

21[+] Cross-User Defacement

22[+] Custom Special Character Injection

23[+] Denial of Service

24[+] Direct Dynamic Code Evaluation (‘Eval Injection’)

25[+] Execution After Redirect (EAR)

26[+] Exploitation of CORS

27[+] Forced browsing : Forcefully browsing content , Or force loading of certain resources without proper authorization.

28[+] Form action hijacking

29[+] Format string attack

30[+] Full Path Disclosure : Disclosing sensitive path in code,comments, directories.

31[+] Function Injection

32[+] Host Header injection : Will be usually performed at host header, eithr the header will be sent with malicous domain or null.

33[+] HTTP Response Splitting

34[+] HTTP verb tampering

35[+] HTML injection

36[+] LDAP injection : LDAP query injection where attacker form  the malicious  inputs which will fetch the system query, Usually works with login scenarios which has ldap as login authorization

37[+] Log Injection

38[+] Man-in-the-browser attack

39[+] Man-in-the-middle attack : Imagine you and your friend were passing sweets , suddenly a stranger comes and snatches your sweets .this is in short explanation, Technically the attacker will act like a proxy and steal up the resources whiehever sent to the server

40[+] Mobile code: invoking untrusted mobile code

41[+] Mobile code: non-final public field

42[+] Mobile code: object hijack

43[+] One-Click Attack

44[+] Parameter Delimiter

45[+] Page takeover

46[+] Path Traversal

47[+] Reflected DOM Injection

48[+] Regular expression Denial of Service – ReDoS

49[+] Repudiation Attack

50[+] Resource Injection

51[+] Server-Side Includes (SSI) Injection

52[+] Session fixation

53[+] Session hijacking attack

54[+] Session Prediction

55[+] Setting Manipulation

56[+] Special Element Injection

57[+] SMTP injection

58[+] SQL Injection

59[+] SSI injection

60[+] Traffic flood

61[+] Web Parameter Tampering

62[+] XPATH Injection

63[+] XSRF or SSRF


Huff ! breath taking isnt it , Will update all in coming days.Thanks.

Comments

Popular Posts