Hacking without credentials
portswigger.net | blog | #attack-surface | #reconnaissance | #web-security | #authentication | #penetration-testing | #portswigger | #recon | #viewstate | #logic-flaws | #login-security
Summary
When a web app exposes only a login form, Dafydd Stuttard lists ways in: fingerprint the stack, brute-force hidden paths, mine HTML comments, tamper with ViewState, and probe login logic flaws.
- Published
- Collected
Skip to content