OSSTM provides a
detailed framework of testing strategies
OWASP is soley to test the security of
web applications and services
NIST Cybersecurity framework is used to
improve an organisations cybersecurity standards
DOM XSS (document Object Model-based Cropss-site scripting)
uses HTML to execute javascript with the
HTML tagPersistent (Service-side) XSS is
javascript that is run when the server loads the page
Reflected (Client-side) XSS is
run on the client side
– in URL suggets what type of attack
SQL injection
Maltego is for
reconnaissance
SQLMap is for
expliotation
Wireshark is for
scanning
Netcat is for
Post-exploitation