官术网_书友最值得收藏!

Manual testing

This is the stage where the tester's presence of mind helps him find various vulnerabilities in the application. In this phase, the attacker manually tests for flaws by fuzzing different input fields and checking the application response. There are times where a scanner will not be able to find certain vulnerabilities and user intervention is much needed, and this is where manual testing prospers. Certain vulnerabilities tend to be missed out by automated scanners, such as :

  • Various business logic flaws
  • Second-order SQL injection 
  • Pentesting cryptographic parameters
  • Privilege escalation
  • Sensitive information disclosures
主站蜘蛛池模板: 新丰县| 永吉县| 元朗区| 和龙市| 郧西县| 仙桃市| 苏尼特右旗| 博野县| 耒阳市| 洛浦县| 丽水市| 从江县| 元氏县| 达州市| 湘潭市| 广宗县| 和静县| 宁国市| 元朗区| 军事| 濮阳市| 镇平县| 定南县| 永福县| 唐河县| 长汀县| 四子王旗| 巴林右旗| 青岛市| 烟台市| 金川县| 桂阳县| 陆良县| 库尔勒市| 水城县| 陇川县| 龙山县| 蓬莱市| 定安县| 长治县| 城市|