Web
Applica+on
Pentes+ng
Vivek
Ramachandran
SWSE,
SMFE,
SPSE,
SISE,
SLAE,
SGDE
Course
Instructor
Cer+fica+ons:
hGp://www.securitytube-‐training.com
Pentester
Academy:
hGp://www.PentesterAcademy.com
©SecurityTube.net
HTTP
Basic
Authen+ca+on
©SecurityTube.net
HTTP
Response
Codes
• 1xx
=
Informa+onal
• 2xx
=
Request
Successful
e.g.
200
OK
• 3xx
=
Redirects
e.g.
302
Moved
Temporarily
• 4xx
=
Client
Request
Errors
e.g.
401
Unauthorized
• 5xx
=
Server
Side
Errors
©SecurityTube.net
Authen+ca+on
in
HTTP
• Basic
Authen+ca+on
• Digest
Authen+ca+on
©SecurityTube.net
Basic
Authen+ca+on
Source:
hGp://docs.oracle.com/cd/E19226-‐01/820-‐7627/bncbo/index.html
©SecurityTube.net
Understanding
HTTP
Basic
Authen+ca+on
• Wireshark
exercise
• Challenge:
HTTP
Basic
Authen+ca+on
AGack
(Easy)
©SecurityTube.net