Real-World Bug Hunting / A Field Guide to Web Hacking
Book information
Description
Learn how people break websites and how you can, too. Real-World Bug Hunting is the premier field guide to finding software bugs. Whether you're a cyber-security beginner who wants to make the internet safer or a seasoned developer who wants to write secure code, ethical hacker Peter Yaworski will show you how it's done. You'll learn about the most common types of bugs like cross-site scripting, insecure direct object references, and server-side request forgery. Using real-life case studies of rewarded vulnerabilities from applications like Twitter, Facebook, Google, and Uber, you'll see how hackers manage to invoke race conditions while transferring money, use URL parameter to cause users to like unintended tweets, and more. Each chapter introduces a vulnerability type accompanied by a series of actual reported bug bounties. The book's collection of tales from the field will teach you how attackers trick users into giving away their sensitive information and how sites may reveal their vulnerabilities to savvy users. You'll even learn how you could turn your challenging new hobby into a successful career. You'll learn: • How the internet works and basic web hacking concepts • How attackers compromise websites • How to identify functionality commonly associated with vulnerabilities • How to find bug bounty programs and submit effective vulnerability reports Real-World Bug Hunting is a fascinating soup-to-nuts primer on web security vulnerabilities, filled with stories from the trenches and practical wisdom. With your new understanding of site security and weaknesses, you can help make the web a safer place--and profit while you're at it. Brief Contents Contents in Detail Foreword Acknowledgments Introduction Who Should Read This Book How to Read This Book What’s in This Book A Disclaimer About Hacking Chapter 1: Bug Bounty Basics Vulnerabilities and Bug Bounties Client and Server What Happens When You Visit a Website Step 1: Extracting the Domain Name Step 2: Resolving an IP Address Step 3: Establishing a TCP Connection Step 4: Sending an HTTP Request Step 5: Server Response Step 6: Rendering the Response HTTP Requests Request Methods HTTP Is Stateless Summary Chapter 2: Open Redirect How Open Redirects Work Shopify Theme Install Open Redirect Takeaways Shopify Login Open Redirect Takeaways HackerOne Interstitial Redirect Takeaways Summary Chapter 3: HTTP Parameter Pollution Server-Side HPP Client-Side HPP HackerOne Social Sharing Buttons Takeaways Twitter Unsubscribe Notifications Takeaways Twitter Web Intents Takeaways Summary Chapter 4: Cross-Site Request Forgery Authentication CSRF with GET Requests CSRF with POST Requests Defenses Against CSRF Attacks Shopify Twitter Disconnect Takeaways Change Users Instacart Zones Takeaways Badoo Full Account Takeover Takeaways Summary Chapter 5: HTML Injection and Content Spoofing Coinbase Comment Injection Through Character Encoding Takeaways HackerOne Unintended HTML Inclusion Takeaways HackerOne Unintended HTML Include Fix Bypass Takeaways Within Security Content Spoofing Takeaways Summary Chapter 6: Carriage Return Line Feed Injection HTTP Request Smuggling v.shopify.com Response Splitting Takeaways Twitter HTTP Response Splitting Takeaways Summary Chapter 7: Cross-Site Scripting Types of XSS Shopify Wholesale Takeaways Shopify Currency Formatting Takeaways Yahoo! Mail Stored XSS Takeaways Google Image Search Takeaways Google Tag Manager Stored XSS Takeaways United Airlines XSS Takeaways Summary Chapter 8: Template Injections Server-Side Template Injections Client-Side Template Injections Uber AngularJS Template Injection Takeaways Uber Flask Jinja2 Template Injection Takeaways Rails Dynamic Render Takeaways Unikrn Smarty Template Injection Takeaways Summary Chapter 9: SQL Injection SQL Databases Countermeasures Against SQLi Yahoo! Sports Blind SQLi Takeaways Uber Blind SQLi Takeaways Drupal SQLi Takeaways Summary Chapter 10: Server-Side Request Forgery Demonstrating the Impact of Server-Side Request Forgery Invoking GET vs. POST Requests Performing Blind SSRFs Attacking Users with SSRF Responses ESEA SSRF and Querying AWS Metadata Takeaways Google Internal DNS SSRF Takeaways Internal Port Scanning Using Webhooks Takeaways Summary Chapter 11: XML External Entity eXtensible Markup Language Document Type Definitions XML Entities How XXE Attacks Work Read Access to Google Takeaways Facebook XXE with Microsoft Word Takeaways Wikiloc XXE Takeaways Summary Chapter 12: Remote Code Execution Executing Shell Commands Executing Functions Strategies for Escalating Remote Code Execution Polyvore ImageMagick Takeaways Algolia RCE on facebooksearch.algolia.com Takeaways RCE Through SSH Takeaways Summary Chapter 13: Memory Vulnerabilities Buffer Overflows Read Out of Bounds PHP ftp_genlist() Integer Overflow Takeaways Python Hotshot Module Takeaways Libcurl Read Out of Bounds Takeaways Summary Chapter 14: Subdomain Takeover Understanding Domain Names How Subdomain Takeovers Work Ubiquiti Subdomain Takeover Takeaways Scan.me Pointing to Zendesk Takeaways Shopify Windsor Subdomain Takeover Takeaways Snapchat Fastly Takeover Takeaways Legal Robot Takeover Takeaways Uber SendGrid Mail Takeover Takeaways Summary Chapter 15: Race Conditions Accepting a HackerOne Invite Multiple Times Takeaways Exceeding Keybase Invitation Limits Takeaways HackerOne Payments Race Condition Takeaways Shopify Partners Race Condition Takeaways Summary Chapter 16: Insecure Direct Object References Finding Simple IDORs Finding More Complex IDORs Binary.com Privilege Escalation Takeaways Moneybird App Creation Takeaways Twitter Mopub API Token Theft Takeaways ACME Customer Information Disclosure Takeaways Summary Chapter 17: OAuth Vulnerabilities The OAuth Workflow Stealing Slack OAuth Tokens Takeaways Passing Authentication with Default Passwords Takeaways Stealing Microsoft Login Tokens Takeaways Swiping Facebook Official Access Tokens Takeaways Summary Chapter 18: Application Logic and Configuration Vulnerabilities Bypassing Shopify Administrator Privileges Takeaways Bypassing Twitter Account Protections Takeaways HackerOne Signal Manipulation Takeaways HackerOne Incorrect S3 Bucket Permissions Takeaways Bypassing GitLab Two-Factor Authentication Takeaways Yahoo! PHP Info Disclosure Takeaways HackerOne Hacktivity Voting Takeaways Accessing PornHub’s Memcache Installation Takeaways Summary Chapter 19: Finding Your Own Bug Bounties Reconnaissance Subdomain Enumeration Port Scanning Screenshotting Content Discovery Previous Bugs Testing the Application The Technology Stack Functionality Mapping Finding Vulnerabilities Going Further Automating Your Work Looking at Mobile Apps Identifying New Fuctionality Tracking JavaScript Files Paying for Access to New Functionality Learning the Technology Summary Chapter 20: Vulnerability Reports Read the Policy Include Details; Then Include More Reconfirm the Vulnerability Your Reputation Show Respect for the Company Appealing Bounty Rewards Summary Appendix A: Tools Web Proxies Subdomain Enumeration Discovery Screenshotting Port Scanning Reconnaissance Hacking Tools Mobile Browser Plug-Ins Appendix B: Resources Online Training Bug Bounty Platforms Recommended Reading Video Resources Recommended Blogs Index
Similar books
Ловушка для багов. Полевое руководство по веб-хакингу
2020 · PDF
Real-World Bug Hunting - A Field Guide to Web Hacking
2019 · PDF
Real-world bug hunting : a field guide to web hacking
2019 · PDF
Real-World Bug Hunting: A Field Guide to Web Hacking
2019 · PDF
Hacking und Bug Hunting: Wie man Softwarefehler aufspürt und damit Geld verdient -- ein Blick über die Schulter eines erfolgreichen Bug Hunters
2020 · EPUB
Real-World Bug Hunting: A Field Guide to Web Hacking
2019 · EPUB
Real-World Bug Hunting: A Field Guide to Web Hacking
2019 · EPUB
Real-World Bug Hunting: A Field Guide to Web Hacking
2019 · EPUB