penetration-testing
How do I provide stdin inputs from command line?
I am trying to perform a buffer overflow attack on a program for a class assignment. Both the attack program as well as the vulnerable programme is written by m开发者_Python百科e.[详细]
2023-03-23 02:19 分类:问答Where can I find an exhaustive list of web attack strings [closed]
As it currentl开发者_C百科y stands, this question is not a good fit for our Q&A format. We expect answers to be supported by facts, references,or expertise, but this question will likely solic[详细]
2023-03-03 07:12 分类:问答How to pass user credentials through Wapiti Web Application Vulnerability Scanner
I would like to test our web application with the Wapiti scanner.In my scenario, I am assuming the attacker would be an authenticated user.How do I configure Wa开发者_开发百科piti to use a specific us[详细]
2023-02-23 08:05 分类:问答Programming/Hacking
Lets say I knew an ethical hacker that I wanted to hire to do a penetration test, but trust was an issue. Could I 开发者_StackOverflow中文版duplicate my system but have its sensitive data removed, and[详细]
2023-02-14 04:44 分类:问答Preparing an ASP.Net website for penetration testing
Over the years I have had a few of the websites I have developed submitted for penetration testing by clients. Most of the time the issues that are highlighted when the results return relate to the de[详细]
2023-01-24 03:45 分类:问答Test code coverage without source code?
What tools are out there that can perform code coverage analysis at the machine code level r开发者_如何学Goather than the source code level?I\'m looking for a possible solution to perform fuzz testing[详细]
2023-01-16 11:21 分类:问答How to validate length of received byte array, which is not null terminated?
I have a C\\C++ code that receives a structure over the network, from this form: struct DataStruct { int DataLen;[详细]
2023-01-13 16:42 分类:问答Security vulnerability testing tool for .NET web applications? [closed]
Closed. This question does not meet Stack Overflow guidelines. It is not currently accepting answers.[详细]
2023-01-11 13:31 分类:问答Penetration testers say that the .ASPXAUTH cookie is insecure and is displaying session data?
I thought the .ASPXAUTH was for user authentication? Can anyone confirm if this cookie is indeed a security risk and/or contains session information? Is it even suppose to be used or开发者_高级运维 is[详细]
2023-01-08 00:10 分类:问答HTTP::Proxy for pen testing tasks
Could someone provide ideas how HTT开发者_JAVA技巧P::Proxy moduleis compared to others proxies like paros and burp proxy and if someone use it during his work specifically if it used by the pen testin[详细]
2023-01-07 04:58 分类:问答