top of page
Search
  • Writer's pictureCharles Wolfe

More Bug Hunting and Uncertainty

Training, training, and more training. That's what the past week has felt like. Up until now, I hadn't really tried to use things like Burp Suite or the Metasploit Framework. Now I just wish I had gotten my feet wet with both of these tools sooner.


The biggest problem is that I have the theory of web application penetration testing down (at least on a basic level), but have little to no experience with actually doing it. I have practiced with manually exploiting SQLi and XSS vulnerabilities but, as I am quickly learning, these are skills that are trivial at worst and complementary at best. In reality, there are a plethora of tools at my disposal built into my Kali Linux virtual machine. I've never been very good about using these sorts of "helper" tools. In many ways I'm a fundamentalist when it comes to this sort of stuff. Seriously, in my math classes, sometimes I would take the time to derive and proof formulas before using them. I digress. The baseline is that I need to familiarize myself with Metasploit and Burp Suite. These "helper" tools are more essential than anything. A computer can ultimately do the grueling job of sifting through TCP logs and HTML requests better than I can manually.

1 view0 comments

Recent Posts

See All

Last Update Before College

Sorry I haven't posted here in a bit. A lot of things have happened. I've finished my final product and, fortunately, it was a veritable success! If you'd like to know more about what happened between

Late-Onset

I have always thought that senioritis would never really hit me. If anything, I thought I had only experienced a short phase of sophomoritis, and that was it. But now that school has been confirmed to

Screw Python

Title says all. I was forced to use Python for last year's machine learning project because that's what the Tensorflow/Keras API was written in. Now that I have access MATLAB/Octave (courtesy of Andre

bottom of page