Note that there are some explanatory texts on larger screens.

plurals
  1. PO
    primarykey
    data
    text
    <p>You should use a combination of automated tools (which can cover off simpler vulnerability assessments very quickly) and manual testing (which is much more time consuming, but allows you to make intelligent dicisions about how to identify issues)</p> <p>Have you looked yet at Metasploit? It is not necessarily the best tool to learn with, but can carry out a wide range of attacks. You can look at the scripted attacks to understand more how each one works.</p> <p>In terms of specific guidance, the tests you must carry out are those listed in the <a href="https://www.owasp.org/index.php/Category%3aOWASP_Top_Ten_Project" rel="nofollow">OWASP top ten</a> as these are the most common attacks of web applications.</p> <p>Becoming an expert in this area is a very long process, and even then it is such a wide field that you will really only be able to focus on one or two areas to become an 'expert' in.</p> <p>I have been in the infosec industry for over 16 years, and I would say that while I have a great deal of experience in infrastructure, Unix and wireless security testing, and have tested web applications in the past, it changes so fast that these days I let my team members who specialise in this area carry out the work. Nowadays I focus on strategy and architecture, as well as governance and compliance.</p> <p>A good first start would be to visit <strong><a href="http://Security.stackexchange.com">Security.stackexchange.com</a></strong>, where we have a wide range of questions and answers on this exact topic, and some very knowledgeable professionals who are active members of the community.</p> <p>I would also recommend getting involved with <a href="https://www.owasp.org/index.php/Main_Page" rel="nofollow">OWASP</a> or having a look at <a href="http://www.isaca.org" rel="nofollow">ISACA</a>, <a href="http://www.instisp.org" rel="nofollow">IISP</a>, <a href="http://www.sans.org" rel="nofollow">SANS</a>, <a href="http://www.crest-approved.org/" rel="nofollow">CREST</a> and other respected bodies.</p>
    singulars
    1. This table or related slice is empty.
    plurals
    1. This table or related slice is empty.
    1. This table or related slice is empty.
    1. This table or related slice is empty.
    1. VO
      singulars
      1. This table or related slice is empty.
    2. VO
      singulars
      1. This table or related slice is empty.
    3. VO
      singulars
      1. This table or related slice is empty.
    1. This table or related slice is empty.
 

Querying!

 
Guidance

SQuiL has stopped working due to an internal error.

If you are curious you may find further information in the browser console, which is accessible through the devtools (F12).

Reload