5 best website pentesting tools on Kali Linux (tutorial)

preview_player
Показать описание
----------------------------------------------------------------------------
Website exploits - begginners guide
---------------------------------------------------------------------------
#ethical_hacking #penetration_testing
Whether you want to find hidden urls / directories or look for SQL Injections and XSS attacks, In this video you can see the best / easiest way to do that. I'm going to use and rank the 5 best website scanners to see which one can capture all the exploits on very vulnerable websites that I have setup.
Those website scanners are free to use and install.

Educational purposes only

I’m going to show how to use:
- Nikto
- Skipfish
- Wapiti
- OWASP-ZAP
- Xsser
With and without authentication on the website.

Chapters:
0:00 Intro
1:05 Nikto: Simple and general vulnerability scanner
2:44 Skipfish: Build a website map and find hidden URLs / files
7:28 Wapiti: Find all vulnerabilities and exploit them from the terminal
11:48 OWASP-ZAP: All exploitations using a GUI
13:37 Xsser: Super good super specialised XSS

Sources:

Setup OWASP-ZAP with DVWA:
Рекомендации по теме
Комментарии
Автор

This video is gold to someone getting started in bounties.. great video!

waylonbraswell
Автор

Super useful video thank you for sharing with us!!!

mdatheeb
Автор

I really enjoyed your video, Nour, and your nice relaxing way to explain things !! May I ask why that link for Setup OWASP-ZAP with DVWA is gone/not working, is it permanent or can I see it somewhere else?? Greetings G

giop
Автор

thanks btrother..next to video "how to fix access file in file directory web browser, , , , after scanner use a zaproxi"..plese

logitechgs
Автор

Btw i must say for api fuzzing and scanning sn1per is amazing for other things also but you get a lot of results in my experience compared to some others.

ZaneEddy
Автор

According to you which is best scanner! wapiti seems me better.

hemanacademyandsecurity
Автор

Could you please inlarge text so it is easier to follow along

scott
Автор

is there any scanner that works on mobile platform for scanning website??

shadowz
Автор

Can I do it in Android as I have installed kali nethunter

Vigilantisim
Автор

How do I get that source address, that address shown in here is not working

siddhubora
Автор

I’m still confused 🤷‍♂️ how do you all get the IP address of your chosen target

ikehkenechukwu