Cross-site request forgery (CSRF)
Cross-Site Request Forgery (CSRF) is an attack that tricks a user’s browser into performing unwanted actions on a trusted web application where the user is authenticated, without their consent. It exploits the trust that a site has in the user’s browser.
Cross-site scripting (XSS)
the attacker executes a malicious script on the victim’s browser after the victim accesses a compromised web application.
Is Prowler open source?
Yes
What benchmarks does Prowler use?
CIS
Prowler is an audit for?
AWS
What can Prowler do?
it can detect misconfigurations and security issues
Is Arachni open source?
Yes
What is Arachni?
is a web application security scanner
What is the dispatcher tab in Arachni for?
dispatcher tab is for remote agents to provide a list of instances to perform scans
What does the input section in Arachni show?
input section show the web input field with an id or user name entry for XSS
What is the profiles section in Arachni for?
profiles section provides a way to manage different scans. They can be personal profiles, shared profiles, and global profiles.
Is Arachni command line?
Yes
What does Nikto do?
web application scanner
Is Nikto command line?
Yes
What does Nikto discover?
discovers the type of HTTP server and web applications running on a host.
Is ScoutSuite open source?
Yes
What does ScoutSuite do?
it is a security auditing tool to assess cloud infractructure security
What is the EC2 dashboard in AWS?
EC2 dashboard is where you find compute instances
What does ZAP do?
attack websites
Is ZAP command line?
No
Is ZAP open source?
Yes
What does ZAP have preconfigured?
a preconfigured browser for testing
Is recon-ng opensource?
Yes
What does recon-ng do?
is a reconnaissance framework tool to map an organization’s network