Skip to main content

Posts

Showing posts from March, 2022

OWASP Web Application Security Testing #1

 Information Gathering ***This blog is connected with one of my YouTube videos. There I have explained about OWASP and this list of OWASP. I'm recommending you to watch it before you read this Blog*** Link -  https://www.youtube.com/watch?v=BNg1KLjgl9I&t=12s&ab_channel=InuraKatulanda   Here, we are understanding the deployed configuration of the server hosting the web application OTG-INFO-001 : Conduct Search Engine Discovery/ Reconnaissance for Information Leakage  There are direct and indirect elements for search engine discovery. Direct Methods related to searching in indexes and the associated content from caches while Indirect Methods related to collecting sensitive design and configuration info by searching forums, newsgroups and tendering websites. There are crawlers in search engines. Once these crawlers are completed crawling, it starts indexing the web page based on the tags and associated attributes. Such as <title>, <head> and so on. C...