官术网_书友最值得收藏!

Manual testing

This is the stage where the tester's presence of mind helps him find various vulnerabilities in the application. In this phase, the attacker manually tests for flaws by fuzzing different input fields and checking the application response. There are times where a scanner will not be able to find certain vulnerabilities and user intervention is much needed, and this is where manual testing prospers. Certain vulnerabilities tend to be missed out by automated scanners, such as :

  • Various business logic flaws
  • Second-order SQL injection 
  • Pentesting cryptographic parameters
  • Privilege escalation
  • Sensitive information disclosures
主站蜘蛛池模板: 漠河县| 察哈| 卢氏县| 桂林市| 江川县| 桃江县| 洛阳市| 抚远县| 措勤县| 铅山县| 吉安县| 酒泉市| 鞍山市| 台江县| 乐平市| 景谷| 横峰县| 陇川县| 西城区| 逊克县| 阜南县| 开江县| 子洲县| 阿瓦提县| 孙吴县| 延吉市| 清丰县| 五峰| 多伦县| 五寨县| 教育| 密云县| 桃园市| 丹凤县| 美姑县| 聂拉木县| 琼结县| 新邵县| 三门县| 柳河县| 汶川县|