Live data from Hacker News

Web Application Penetration Testing Cheat Sheet

jdow.io

1–10 of 40 posts

Re: Web Application Penetration Testing Cheat Sheet

#7

This looks cool! I have the other perspective -- I have a site that I want secured. This seems helpful for that angle also. I'd be interested if there are other resources as well that could be suggested on this thread!

You should check out the youtube channel LiveOverflow [0], it's mostly about infosec and pentesting. As someone who is neither into infosec nor pentesting, I found it to be a very interesting and informative channel which improved my understanding of coding and security in general.

[0] https://www.youtube.com/channel/UClcE-kVhqyiHCcjYwcpfj9w/fea...

Re: Web Application Penetration Testing Cheat Sheet

#9

Be sure to let AWS know you are pentesting before you start testing your app hosted there. https://aws.amazon.com/security/penetration-testing/

Commentary in the spirit of security automation:

Of course Amazon still compels a human review.

By contrast, Google App Engine and Microsoft Azure are fine with you doing it on your own provided you're not a moron.

https://support.google.com/cloud/answer/6262505?hl=en

https://docs.microsoft.com/en-us/azure/security/azure-securi...

(I deal with AWS, Azure, and GAE across multiple companies. heh)

Post reply on HN