Your hand is in the cookie jar

Categories
OWASP Mth3l3m3nt, Uncategorized, Web Attacks, webdev

It’s been a while since my last “confession”. So today I’m here to tell you that sadly “I placed my hand in the cookie jar”. Pfffffffft!!!!! There’s a nifty new feature in the OWASP mth3l3m3nt framework  that you just might love, it was inspired by pentest tools. It aims to give potency to Cross Site Scripting […]

Man In The DOM (MiTD)

Categories
Injection, Projects, Uncategorized, Web Attacks

You are in the middle of an assessment , things are thick. SE is the only option but you are short on time. Users however are sloppy and the question begs to ask:   What’s the Worst that could happen on an unlocked screen for a few minutes? Well Take these pointers at hand: Users Leave […]

Password Field Unmasker

Categories
Uncategorized, Web Attacks

When performing a penetration test on applications on the web especially in form fields that deal with password functions e.g. Database configuration forms , User Listing pages, you may want to know whether it echoes back the password in plain text which is usually a bad practice. It is particularly useful in mass revealing of […]

Installing OWASP Mth3l3m3nt Framework on Linux

Categories
OWASP Mth3l3m3nt, Uncategorized

The installation of Mth3l3m3nt has been made as easy as possible. The first step though is getting the server configuration to work well to achieve three things: Disable Directory Listing Enable Htaccess overrides Allow Includes and Symlinking for dynamic routes to work. This can all be found in the article here. Alternatively watch the video […]

HackBattle 2015 – Scenario 1- Part 1

Categories
ctf, HB 2015, Uncategorized, Web Attacks

The HackBattle this year was themed ROTT (“Rampage of the trolls”) The infrastructure is courtesy of Azanuru Technologies. It was announced on various platforms on social media for people to participate in over a period of 4 weeks. This was testing key skills including The main aim was to help people understand how to develop […]