Web Hacking: un po' di siti per imparare
Vi segnalo questo utile post che elenca diversi siti Web per imparare un po' di Web hacking. Sono siti creati appositamente a questo scopo e permettono a tutti di sperimentare le più disparate tecniche di hacking. In modo manuale e/o con tool di supporto quali WebApp Scanner. Nella lista infatti si possono riconoscere i maggiori produttori di Web App Security.
Riporto per comodità la lista:
- SPI Dynamics (live) – http://zero.webappsecurity.com/
- Cenzic (live) – http://crackme.cenzic.com/
- Watchfire (live) – http://demo.testfire.net/
- Acunetix (live) – http://testphp.acunetix.com/ http://testasp.acunetix.com http://testaspnet.acunetix.com
- PCTechtips Challenge (live) - http://pctechtips.org/hacker-challenge-pwn3d-the-login-form/
- Damn Vulnerable Web Application – http://dvwa.co.uk/
- Mutillidae – http://www.irongeek.com/i.php?page=security/mutillidae-deliberately-vulnerable-php-owasp-top-10
- The Butterfly Security Project – http://sourceforge.net/projects/thebutterflytmp/files/ButterFly%20Project/
- Hacme Casino – http://www.foundstone.com/us/resources/proddesc/hacmecasino.htm
- Hacme Bank 2.0 – http://www.foundstone.com/us/resources/proddesc/hacmebank.htm
- Updated HackmeBank – http://www.o2-ounceopen.com/technical-info/2008/12/8/updated-version-of-hacmebank.html
- Hacme Books – http://www.foundstone.com/us/resources/proddesc/hacmebooks.htm
- Hacme Travel – http://www.foundstone.com/us/resources/proddesc/hacmetravel.htm
- Hacme Shipping - http://www.foundstone.com/us/resources/proddesc/hacmeshipping.htm
- OWASP WebGoat – http://www.owasp.org/index.php/OWASP_WebGoat_Project
- OWASP Vicnum – http://www.owasp.org/index.php/Category:OWASP_Vicnum_Project
- OWASP InsecureWebApp –http://www.owasp.org/index.php/Category:OWASP_Insecure_Web_App_Project
- OWASP SiteGenerator – http://www.owasp.org/index.php/Owasp_SiteGenerator
- Moth - http://www.bonsai-sec.com/en/research/moth.php
- Stanford SecuriBench – http://suif.stanford.edu/~livshits/securibench/
- SecuriBench Micro – http://suif.stanford.edu/~livshits/work/securibench-micro/
- BadStore – http://www.badstore.net/
- WebMaven/Buggy Bank – http://www.mavensecurity.com/webmaven (very old)
- Exploit-DB – http://www.exploit-db.com/webapps (some vulnerable web applications are provided as downloads)
Ora non vi resta che "sprecare" un po' di tempo per analizzarle. Non pensiate che sia così semplice bucarle però. Buona fortuna!
Commenti
Posta un commento