21. Web Application Testing Tools
Chala mitrano, aaj internet cha saglyat motha hallya-cha area – web applications. Tumhi Chapter 9 te 16 madhe swatah PHP website, LAMP/LEMP aani reels app banavla. Aata tya hi najrene baghuya jashi ek attacker baghto: form madhe kay taklyavar kay hote, URL badalla tar kay hote, hidden pages kuthe aahet. Ha chapter tools cha aahe – Burp Suite, ZAP, Gobuster, sqlmap, WPScan. Pratyek tool fakt DVWA, Juice Shop kiwa tumchya swatahchya reels app var. Baherchya konatyahi site var nahi – to gunha aahe. Samjla ka? Chala!
What you will learn in this chapter
- How web traffic works and why a proxy is the tester's main tool
- Burp Suite: proxy, intercept, repeater and intruder (community edition)
- OWASP ZAP: a free alternative with automated scanning
- Gobuster and Dirb: finding hidden directories and files
- sqlmap: testing for and confirming SQL injection safely
- WPScan: checking WordPress sites
- Turning every attack into a defence for the apps you built earlier
Lab scope for this whole chapter
Run every tool here only against DVWA, OWASP Juice Shop, or your own reels app from Chapter 16, all on your host-only lab. Automated web attacks against a site you do not own are illegal under the IT Act, even as a "test".
Concepts in this chapter
- 21.1How Web Testing Works: The Intercepting Proxy
- 21.2Burp Suite: Proxy and Intercept
- 21.3Burp Intruder: Automating Requests
- 21.4OWASP ZAP: A Free Full Scanner
- 21.5Gobuster and Dirb: Finding Hidden Content
- 21.6sqlmap: Testing for SQL Injection
- 21.7WPScan: Scanning WordPress
- 21.8Red vs Blue, Project and Real Incidents
The chapter recap is at the end of the last concept page.