Pentesting2015: Difference between revisions
Jump to navigation
Jump to search
No edit summary |
|||
Line 16: | Line 16: | ||
==Wörterbücher== |
==Wörterbücher== |
||
https://wiki.skullsecurity.org/Passwords |
https://wiki.skullsecurity.org/Passwords |
||
https://crackstation.net/buy-crackstation-wordlist-password-cracking-dictionary.htm |
https://crackstation.net/buy-crackstation-wordlist-password-cracking-dictionary.htm |
Revision as of 09:20, 29 September 2015
Wikiseite für das Thema Pentesting vom IT-Security Workshop 2015.
allgemeine Planung
Einarbeitung ins Pentesting für Web-Applikationen mit Hilfe von dvwa.
Links
- dvwa : http://www.dvwa.co.uk/
- installation von dvwa auf ubuntu server: http://hackthistv.com/blog/how-to-install-dvwa-on-ubuntu-server-14-04/
- alte Projekte: http://blog.taddong.com/2011/10/hacking-vulnerable-web-applications.html
- VMs: https://www.owasp.org/index.php/OWASP_Vulnerable_Web_Applications_Directory_Project/Pages/VMs
- Applikationen: https://github.com/OWASP/OWASP-VWAD/blob/master/src/offline.tsv
- intercepting Proxy: https://portswigger.net/burp/download.html
- Applikations, Virtual Machines und ISOs (siehe jeweils Tab): https://www.owasp.org/index.php/OWASP_Vulnerable_Web_Applications_Directory_Project#tab=On-Line_apps
Wörterbücher
https://wiki.skullsecurity.org/Passwords
https://crackstation.net/buy-crackstation-wordlist-password-cracking-dictionary.htm