Chapter 7. Web Application Scanning
In the past years, we have seen increasing media coverage about major corporate and government data breaches. And, as general awareness about security has increased, it has become more and more difficult to infiltrate an organization's networks by exploiting standard perimeter services. Publicly known vulnerabilities associated with these services are often quickly patched and leave little available attack surface. On the contrary, web applications often contain custom code that usually does not undergo the same amount of public scrutiny that a network service from an independent vendor will endure. Web applications are often the weakest point on an organization's perimeter, and as such, appropriate scanning and evaluation of these services is critical. This chapter will include the following recipes for performing web application vulnerability scanning:
- Web application scanning with Nikto
- SSL/TLS scanning with SSLScan
- SSL/TLS scanning...