From the course: CompTIA CySA+ (CS0-002) Cert Prep: 2 Vulnerability Management (2020)
Unlock the full course today
Join today to access over 22,600 courses taught by industry experts or purchase this course individually.
Interception proxies
From the course: CompTIA CySA+ (CS0-002) Cert Prep: 2 Vulnerability Management (2020)
Interception proxies
- [Instructor] Interception proxies are an important tool used during the penetration testing of web applications. During normal use of the web a user launches a web browser on his or her computer and he uses it to retrieve information from web servers. The user's web browser creates requests using HTTP the HyperText Transfer Protocol, the browser then sends those requests to web servers and the web servers reply with the requested information. When a penetration tester targets a web application, he or she usually wants to manipulate the HTTP request sent to a website so that they contain malicious requests. Now websites aren't set up to accommodate these malicious requests so the tester needs some additional help. Interception proxies fit this need by intercepting the requests sent by the tester's browser before they're sent to the web server. The interception proxy then allows the tester to manipulate the request before it's…
Contents
-
-
-
-
-
-
-
-
(Locked)
OWASP (Open Web Application Security Project)5m 24s
-
(Locked)
Preventing SQL injection5m 29s
-
(Locked)
Understanding cross-site scripting6m 38s
-
(Locked)
Privilege escalation2m 14s
-
(Locked)
Directory traversal3m 16s
-
(Locked)
Race conditions2m 39s
-
(Locked)
Dereferencing NULL pointers2m 33s
-
(Locked)
Third-party code5m 40s
-
(Locked)
Interception proxies5m 22s
-
(Locked)
-
-
-