Web applications sometimes use system commands as part of their features. Imagine a web application that lets you enter an IP address, then pings this address to check if the host is accessible. In order to do this, the app could maybe use the ping command to do the job. Bottom line: a web app...
What is XSS – Cross Site Scripting?
XSS or Cross Site Scripting is a technique that allows malicious users to insert JavaScript code into a page from a target web site. When the page is then displayed or refreshed, the attacker’s JavaScript is executed by the browser just like any legit JavaScript code contained in the code of the page. If...
Clusterbomb or pitchfork?
Clusterbomb and pitchfork are terms you will come across when fuzzing web apps using tools like FFUF or Burp Suite. Let’s see how this works with FFUF. FFUF has two wordlist modes : clusterbomb and pitchfork. These modes will matter when you want to fuzz two separate positions in your target URL, using two wordlists. Here...
What is FFUF?
FFUF is a command line tool that helps you find hidden endpoints in web apps (files and directories that are not linked by another page on the same web site or from the Internet). Hackers use FFUF to widen their attack surface by mapping out the target web site more extensively than what they...
What is Dirb?
Dirb is a command line tool you can use to fuzz web sites or web apps. Dirb finds files and directories on your target site that are not directly linked from a publicly accessible page on the site or from the Internet. This means Dirb can map out your target beyond what you may...