Scanning Web Servers

This chapter covers the following recipes:

  • Listing supported HTTP methods
  • Checking whether a web server is an open proxy
  • Discovering interesting files and folders in web servers
  • Abusing mod_userdir to enumerate user accounts
  • Brute forcing HTTP authentication
  • Brute forcing web applications
  • Detecting web application firewalls
  • Detecting possible XST vulnerabilities
  • Detecting XSS vulnerabilities
  • Finding SQL injection vulnerabilities
  • Detecting web servers vulnerable to slowloris denial of service attacks
  • Finding web applications with default credentials
  • Detecting web applications vulnerable to Shellshock
  • Detecting insecure cross-domain policies
  • Detecting exposed source code control systems
  • Auditing the strength of cipher ...

Get Nmap: Network Exploration and Security Auditing Cookbook - Second Edition now with the O’Reilly learning platform.

O’Reilly members experience books, live events, courses curated by job role, and more from O’Reilly and nearly 200 top publishers.