3 ms·
If you want to start looking at application layer pentesting I would review the owasp top 10 and then see how you can apply it to your current projects. I'm co
by evilnames 7y ago
If you want to start looking at application layer pentesting I would review the owasp top 10 and then see how you can apply it to your current projects. I'm constantly using this list and other tricks on any sensitive site that my data resides to hone my skills and make sure there isn't any dumb security flaws that will leak my information. The sad thing is that you'll find cracks in the armor of almost any web service that you use.
I think the most basic test you can practice is just changing the URL if you see a number in it. If you change the number should you see the information that is at the new number? Yes reveals a lot about the website and it's security measures and will let you keep poking further.
Last thing I'll say is, as you practice and learn do not be malicious, even if you could delete an entire set of data because of bad permissions, don't do it. Most, like 90% of companies are relatively appreciative of being told about an exploit. There are some that are not however :(
Practice makes perfect, if you can get marginally better at security them you will write better code and better applications so go for it!