00:00/00:00

This lesson explores easy-to-exploit server and website vulnerabilities, including automated SQL injections with tools like Katusha, exposed .env files on repositories like GitHub, and open databases lacking default authentication.

Server and Website Vulnerabilities: Low-Hanging Fruits in Cybersecurity copy

24:40Study Material
In this lesson, we delve into how attackers exploit servers and websites with minimal effort. We cover the history of Katusha, an automated credit card extraction tool that used search engine dorking, Arachne Web Scanner, and SQL Map to compromise targets. The lesson highlights the severe danger of exposing .env files containing API keys and database passwords on platforms like GitHub or live servers. Furthermore, we examine the security risks of databases like Elasticsearch, Redis, MongoDB, and CouchDB that historically lacked default authentication configurations. Additional topics include finding exposed management tools like PHPMyAdmin and using automated scanners like afrog and DB scanner to identify default credentials and network vulnerabilities.
Watch until the end to complete this lesson
0% watched
Back to Course

Tags

SQL injectionKatushaSQL mapArachne Web Scanner.env fileGitHubShodanElasticsearchPHPMyAdminDefault passwordsafrog