Login or register
SecDocs RSS feed

Paper details

Title Constricting the Web: Offensive Python for Web Hackers
Type Paper
Tags web application web python
Abstract It seems that everything is a web application nowadays. Whether the application is cloud-based, mobile, or even fat client they all seem to be using web protocols to communicate. Adding to the traditional landscape there is rise in the use of application programming interfaces, integration hooks, and next generation web technologies. What this means for someone testing web applications is that flexibility is the key to success. The Python programming language is just as flexible as today’s web application platforms. The language is appealing to security professionals because it is easy to read and write, has a wide variety of modules, and has plenty of resources for help. This additional flexibility affords the tester greater depth than many of the canned tests that come with common tools they use on a daily basis. Greater familiarity plus flexible language equals tester win! In this presentation we introduce methods with which to create your own clients, tools, and test cases using the Python programming language. We want to put testers closer to the conditions in which they are testing for and arm them with the necessary resources to be successful. We also discuss interfacing with current tools that people commonly use for web application testing. This allows for pinpoint identification of specific vulnerabilities and conditions that are difficult for other tools to identify.
Authors Marcin Wielgoszewski Nathan Hamiel
Submitted September 13, 2011
Rating
Currently 0/5 stars (0 votes).
Correlation
Linked to
Event Black Hat USA 2010
Resource ---
Download
Source BlackHat-USA-2010-Hamiel-Wielgosweski-Constricting-the-Web-wp.pdf
Size 167.3 KB
MD5 0caa0862706fcf14a88179ff7500e32d
SHA1 faca90ed717cd73987b4d573c5d9f7ab3d87f05f

Comments
No comments.
Add new Only logged in users can comment.


Click here to lend your support to: SecDocs and make a donation at www.pledgie.com !