Web Application VAPT - Framework


A - Java: Spring Framework

A1: Directory traversal with static resource handling (CVE-2014-3625)
  • https://pivotal.io/security/cve-2014-3625

A2: Spring Boot Actuator
  • /autoconfig
  • /beans
  • /configprops
  • /dump
  • /env
  • /health
  • /info
  • /metrics
  • /mappings
  • /trace
Reference:
https://docs.spring.io/spring-security/site/docs/5.0.0.RELEASE/reference/html5/#new





Popular posts from this blog

Remote Desktop Protocol (RDP) Security

Penetration Testing - Network

Damn Vulnerable Web Services (DVWS) - Walkthrough

Server Message Block (SMB) Security

Offensive Security Testing Guide

Host Configuration Assessment - Windows

Web Server Hardening - Apache Tomcat

Content Page

Mobile Penetration Testing - Android

Penetration Testing with OWASP Top 10 - 2017 A7 Cross-Site Scripting (XSS)