• Log In
  • Skip to primary navigation
  • Skip to main content
  • Skip to primary sidebar
  • HomePage
  • About
  • Structure
  • Schedule
    • First Half of the Semester
      • Week 1: Course Introduction
      • Week 2: IT’s Role and the Control Environment
      • Week 3: Social Engineering Toolkit, SQL Injection, Karmetasploit, Building Modules in Metasploit, and Creating Exploits
      • Week 4: Porting Exploits, Scripting, and Simulating Penetration Testing Ettercap
      • Week 5: Introduction to OWASP’s WebGoat application
      • Week 6: Unvalidated Parameters, Broken Access Control, and Broken Authentication
      • Week 7: Cross Site Scripting, Injection Flaws, Error Handling, and Insecure Storage
    • Second Half of the Semester
      • Week 8: Denial of Service, Configuration Management, and Web Services
      • Week 9: Ajax Security and an Introduction to the WebGoat Challenge Wireshark
      • Week 10: Introduction to Wireless Security
      • Week 11: Wireless Recon, WEP, and WPA2
      • Week 12: WPA2 Enterprise, Wireless beyond WiFi
      • Week 13: Cain and Able
  • Assignments
    • Analysis Reports
    • Quizzes & Tests
  • Webex
  • Harvard Coursepack
  • Roster
  • Gradebook

ITACS 5212: Advanced Penetration Testing

Wade Mackay

Week 6: Unvalidated Parameters, Broken Access Control, and Broken Authentication

Readings:

http://cdn.ttgtmedia.com/rms/pdf/SearchSecurity.in_Burp_%20Suite_tutorial_Part_01.pdf

 

http://cdn.ttgtmedia.com/rms/pdf/SearchSecurity.in_Burp_%20Suite_tutorial_Part_02.pdf

 

http://cdn.ttgtmedia.com/rms/pdf/SearchSecurity.in_Burp_%20Suite_tutorial_Part_03.pdf

 

We will only use the functionality discussed in the first paper.

 

http://www.sans.org/reading-room/whitepapers/application/web-application-injection-vulnerabilities-web-app-039-s-security-nemesis-34247

 

http://www.sans.org/reading-room/whitepapers/application/web-application-security-for-managers-27

Primary Sidebar

Weekly Discussions

  • Uncategorized (1)

Copyright © 2025 · Magazine Pro Theme on Genesis Framework · WordPress · Log in