官术网_书友最值得收藏!

Stages of an application pentest

It is trivial to understand the stages of an application pentest as it lays the groundwork and ensures that the pentester covers all the possible endpoints and does an efficient scan. A web application pentest is broadly categorized in the following stages:

  • Planning and reconnaissance
  • Client end code analysis
  • Manual testing 
  • Automated testing
  • Exploiting discovered issues 
  • Digging deep for data exfiltration
  •  Taking shells
  • Reporting

Among these stages, the planning and reconnaissance stage is the most important stage, as there are possibilities that a tester might miss out critical entry endpoints into the application, and those areas might go untested. Let's explore in a little more detail what happens in each stage.

主站蜘蛛池模板: 静安区| 荣昌县| 新河县| 轮台县| 铜梁县| 闽清县| 鄂托克前旗| 波密县| 南华县| 上杭县| 鸡泽县| 佛坪县| 峨眉山市| 乾安县| 纳雍县| 霍邱县| 凤山市| 汶上县| 托里县| 鄱阳县| 化德县| 武陟县| 扎囊县| 神池县| 漯河市| 昭觉县| 伽师县| 开鲁县| 南通市| 德阳市| 名山县| 泸西县| 长顺县| 新龙县| 闻喜县| 禄劝| 沁源县| 萝北县| 秭归县| 梁山县| 辽宁省|