Python Web Penetration Testing Cookbook
暫譯: Python 網頁滲透測試食譜

Cameron Buchanan, Terry Ip, Andrew Mabbitt, Benjamin May, Dave Mound

  • 出版商: Packt Publishing
  • 出版日期: 2015-06-19
  • 售價: $2,000
  • 貴賓價: 9.5$1,900
  • 語言: 英文
  • 頁數: 228
  • 裝訂: Paperback
  • ISBN: 1784392936
  • ISBN-13: 9781784392932
  • 相關分類: Python程式語言Penetration-test
  • 海外代購書籍(需單獨結帳)

相關主題

商品描述

Over 60 indispensable Python recipes to ensure you always have the right code on hand for web application testing

About This Book

  • Get useful guidance on writing Python scripts and using libraries to put websites and web apps through their paces
  • Find the script you need to deal with any stage of the web testing process
  • Develop your Python knowledge to get ahead of the game for web testing and expand your skillset to other testing areas

Who This Book Is For

This book is for testers looking for quick access to powerful, modern tools and customizable scripts to kick-start the creation of their own Python web penetration testing toolbox.

What You Will Learn

  • Enumerate users on web apps through Python
  • Develop complicated header-based attacks through Python
  • Deliver multiple XSS strings and check their execution success
  • Handle outputs from multiple tools and create attractive reports
  • Create PHP pages that test scripts and tools
  • Identify parameters and URLs vulnerable to Directory Traversal
  • Replicate existing tool functionality in Python
  • Create basic dial-back Python scripts using reverse shells and basic Python PoC malware

In Detail

This book gives you an arsenal of Python scripts perfect to use or to customize your needs for each stage of the testing process. Each chapter takes you step by step through the methods of designing and modifying scripts to attack web apps. You will learn how to collect both open and hidden information from websites to further your attacks, identify vulnerabilities, perform SQL Injections, exploit cookies, and enumerate poorly configured systems. You will also discover how to crack encryption, create payloads to mimic malware, and create tools to output your findings into presentable formats for reporting to your employers.

商品描述(中文翻譯)

超過 60 個不可或缺的 Python 範例,確保您隨時擁有適合的程式碼來進行網頁應用程式測試

本書簡介



  • 獲得有關撰寫 Python 腳本和使用函式庫的實用指導,以測試網站和網頁應用程式

  • 找到您需要的腳本,以處理網頁測試過程的任何階段

  • 發展您的 Python 知識,讓您在網頁測試中領先一步,並擴展您的技能到其他測試領域

本書適合誰閱讀


本書適合尋求快速訪問強大、現代工具和可自訂腳本的測試人員,以啟動他們自己的 Python 網頁滲透測試工具箱的創建。

您將學到什麼



  • 通過 Python 列舉網頁應用程式的使用者

  • 通過 Python 開發複雜的基於標頭的攻擊

  • 傳送多個 XSS 字串並檢查其執行成功

  • 處理來自多個工具的輸出並創建吸引人的報告

  • 創建測試腳本和工具的 PHP 頁面

  • 識別易受目錄遍歷攻擊的參數和 URL

  • 在 Python 中複製現有工具的功能

  • 使用反向 Shell 和基本的 Python PoC 惡意軟體創建基本的回撥 Python 腳本

詳細內容


本書提供了一系列完美的 Python 腳本,適合用於或根據您的需求自訂每個測試過程的階段。每一章都逐步引導您設計和修改腳本以攻擊網頁應用程式的方法。您將學習如何從網站收集公開和隱藏的信息,以進一步進行攻擊,識別漏洞,執行 SQL 注入,利用 Cookies,並列舉配置不當的系統。您還將發現如何破解加密,創建模擬惡意軟體的有效載荷,並創建工具將您的發現輸出為可報告的格式,以便向您的雇主報告。