{"id":486,"date":"2026-06-18T14:17:42","date_gmt":"2026-06-18T10:47:42","guid":{"rendered":"https:\/\/blog.radnetco.com\/?p=486"},"modified":"2026-06-18T14:17:46","modified_gmt":"2026-06-18T10:47:46","slug":"%d8%b1%d8%a7%d9%87%d9%86%d9%85%d8%a7%db%8c-%d8%ac%d8%a7%d9%85%d8%b9-%d8%aa%d8%b3%d8%aa-%d9%86%d9%81%d9%88%d8%b0-%d9%86%d8%b1%d9%85%d8%a7%d9%81%d8%b2%d8%a7%d8%b1%d9%87%d8%a7%db%8c-%d8%aa%d8%ad","status":"publish","type":"post","link":"https:\/\/blog.radnetco.com\/?p=486","title":{"rendered":"\u0631\u0627\u0647\u0646\u0645\u0627\u06cc \u062c\u0627\u0645\u0639 \u062a\u0633\u062a \u0646\u0641\u0648\u0630 \u0646\u0631\u0645\u200c\u0627\u0641\u0632\u0627\u0631\u0647\u0627\u06cc \u062a\u062d\u062a \u0648\u0628 \u0628\u0631 \u0627\u0633\u0627\u0633 \u0622\u062e\u0631\u06cc\u0646 \u0627\u0633\u062a\u0627\u0646\u062f\u0627\u0631\u062f\u0647\u0627\u06cc \u0627\u0645\u0646\u06cc\u062a\u06cc \u062f\u0646\u06cc\u0627"},"content":{"rendered":"\n<p class=\"wp-block-paragraph\">\u0631 \u0628\u0633\u06cc\u0627\u0631\u06cc \u0627\u0632 \u0633\u0627\u0632\u0645\u0627\u0646\u200c\u0647\u0627\u060c \u0627\u0645\u0646\u06cc\u062a \u0646\u0631\u0645\u200c\u0627\u0641\u0632\u0627\u0631 \u0628\u0647 \u0627\u062c\u0631\u0627\u06cc \u0686\u0646\u062f \u0627\u0633\u06a9\u0646 \u0627\u062a\u0648\u0645\u0627\u062a\u06cc\u06a9 \u0628\u0627 \u0627\u0628\u0632\u0627\u0631\u0647\u0627\u06cc\u06cc \u0645\u0627\u0646\u0646\u062f Burp Suite \u06cc\u0627 Acunetix \u0645\u062d\u062f\u0648\u062f \u0645\u06cc\u200c\u0634\u0648\u062f\u060c \u062f\u0631 \u062d\u0627\u0644\u06cc \u06a9\u0647 \u062d\u0645\u0644\u0627\u062a \u0648\u0627\u0642\u0639\u06cc \u0645\u0647\u0627\u062c\u0645\u0627\u0646 \u0628\u0633\u06cc\u0627\u0631 \u067e\u06cc\u0686\u06cc\u062f\u0647\u200c\u062a\u0631 \u0627\u0632 \u0622\u0633\u06cc\u0628\u200c\u067e\u0630\u06cc\u0631\u06cc\u200c\u0647\u0627\u06cc \u0634\u0646\u0627\u062e\u062a\u0647\u200c\u0634\u062f\u0647 OWASP Top 10 \u0647\u0633\u062a\u0646\u062f.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">\u062f\u0631 \u0634\u0631\u06a9\u062a \u0628\u0631\u0646\u0627\u0645\u0647\u200c\u0646\u0648\u06cc\u0633\u06cc \u0631\u0627\u062f\u0646\u062a\u060c \u062a\u0633\u062a \u0646\u0641\u0648\u0630 \u0635\u0631\u0641\u0627\u064b \u0628\u0647 \u0645\u0639\u0646\u06cc \u06cc\u0627\u0641\u062a\u0646 SQL Injection \u06cc\u0627 XSS \u0646\u06cc\u0633\u062a\u060c \u0628\u0644\u06a9\u0647 \u06cc\u06a9 \u0641\u0631\u0627\u06cc\u0646\u062f \u0686\u0646\u062f\u0645\u0631\u062d\u0644\u0647\u200c\u0627\u06cc \u0645\u0628\u062a\u0646\u06cc \u0628\u0631 \u0627\u0633\u062a\u0627\u0646\u062f\u0627\u0631\u062f\u0647\u0627\u06cc OWASP WSTG\u060c ASVS\u060c PTES \u0648 NIST SP 800-115 \u0645\u062d\u0633\u0648\u0628 \u0645\u06cc\u200c\u0634\u0648\u062f \u06a9\u0647 \u0647\u062f\u0641 \u0622\u0646 \u06a9\u0634\u0641 \u0636\u0639\u0641\u200c\u0647\u0627\u06cc \u0627\u0645\u0646\u06cc\u062a\u06cc \u062f\u0631 \u0633\u0637\u062d \u0645\u0639\u0645\u0627\u0631\u06cc\u060c \u0645\u0646\u0637\u0642 \u062a\u062c\u0627\u0631\u06cc\u060c API\u0647\u0627\u060c Session\u0647\u0627 \u0648 \u0632\u06cc\u0631\u0633\u0627\u062e\u062a \u0646\u0631\u0645\u200c\u0627\u0641\u0632\u0627\u0631 \u0627\u0633\u062a.<\/p>\n\n\n\n<hr class=\"wp-block-separator has-alpha-channel-opacity\"\/>\n\n\n\n<figure class=\"wp-block-image size-large\"><img loading=\"lazy\" decoding=\"async\" width=\"1024\" height=\"489\" src=\"https:\/\/blog.radnetco.com\/wp-content\/uploads\/2026\/06\/threats-1024x489.png\" alt=\"\" class=\"wp-image-488\" srcset=\"https:\/\/blog.radnetco.com\/wp-content\/uploads\/2026\/06\/threats-1024x489.png 1024w, https:\/\/blog.radnetco.com\/wp-content\/uploads\/2026\/06\/threats-300x143.png 300w, https:\/\/blog.radnetco.com\/wp-content\/uploads\/2026\/06\/threats-150x72.png 150w, https:\/\/blog.radnetco.com\/wp-content\/uploads\/2026\/06\/threats-768x367.png 768w, https:\/\/blog.radnetco.com\/wp-content\/uploads\/2026\/06\/threats.png 1259w\" sizes=\"auto, (max-width: 1024px) 100vw, 1024px\" \/><\/figure>\n\n\n\n<h1 class=\"wp-block-heading\">\u0641\u0627\u0632 \u0627\u0648\u0644: Information Gathering<\/h1>\n\n\n\n<h3 class=\"wp-block-heading\">Passive Reconnaissance<\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">\u062c\u0645\u0639\u200c\u0622\u0648\u0631\u06cc \u0627\u0637\u0644\u0627\u0639\u0627\u062a \u0628\u062f\u0648\u0646 \u062a\u0639\u0627\u0645\u0644 \u0645\u0633\u062a\u0642\u06cc\u0645:<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li>DNS Enumeration<\/li>\n\n\n\n<li>WHOIS<\/li>\n\n\n\n<li>Certificate Transparency Logs<\/li>\n\n\n\n<li>Google Dorking<\/li>\n\n\n\n<li>GitHub Recon<\/li>\n\n\n\n<li>Shodan Enumeration<\/li>\n\n\n\n<li>\u062a\u062d\u0644\u06cc\u0644 JavaScript\u0647\u0627<\/li>\n\n\n\n<li>\u06a9\u0634\u0641 Subdomain\u0647\u0627<\/li>\n<\/ul>\n\n\n\n<p class=\"wp-block-paragraph\">\u0627\u0628\u0632\u0627\u0631\u0647\u0627:<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li>Amass<\/li>\n\n\n\n<li>Subfinder<\/li>\n\n\n\n<li>Assetfinder<\/li>\n\n\n\n<li>Shodan<\/li>\n\n\n\n<li>Wayback Machine<\/li>\n<\/ul>\n\n\n\n<hr class=\"wp-block-separator has-alpha-channel-opacity\"\/>\n\n\n\n<h3 class=\"wp-block-heading\">Active Reconnaissance<\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">\u0634\u0646\u0627\u0633\u0627\u06cc\u06cc \u0633\u0637\u062d \u062d\u0645\u0644\u0647:<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li>Port Scanning<\/li>\n\n\n\n<li>Service Enumeration<\/li>\n\n\n\n<li>Banner Grabbing<\/li>\n\n\n\n<li>SSL Analysis<\/li>\n\n\n\n<li>Directory Bruteforce<\/li>\n<\/ul>\n\n\n\n<p class=\"wp-block-paragraph\">\u0627\u0628\u0632\u0627\u0631\u0647\u0627:<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li>Nmap<\/li>\n\n\n\n<li>Masscan<\/li>\n\n\n\n<li>Feroxbuster<\/li>\n\n\n\n<li>Gobuster<\/li>\n\n\n\n<li>SSLScan<\/li>\n<\/ul>\n\n\n\n<hr class=\"wp-block-separator has-alpha-channel-opacity\"\/>\n\n\n\n<h1 class=\"wp-block-heading\">\u0641\u0627\u0632 \u062f\u0648\u0645: Authentication Testing<\/h1>\n\n\n\n<p class=\"wp-block-paragraph\">\u0628\u0631\u0631\u0633\u06cc \u0633\u06cc\u0633\u062a\u0645 \u0627\u062d\u0631\u0627\u0632 \u0647\u0648\u06cc\u062a<\/p>\n\n\n\n<h3 class=\"wp-block-heading\">User Enumeration<\/h3>\n\n\n\n<ul class=\"wp-block-list\">\n<li>\u062a\u0641\u0627\u0648\u062a \u067e\u06cc\u0627\u0645\u200c\u0647\u0627\u06cc \u062e\u0637\u0627<\/li>\n\n\n\n<li>\u0632\u0645\u0627\u0646 \u067e\u0627\u0633\u062e<\/li>\n\n\n\n<li>Password Reset Leakage<\/li>\n<\/ul>\n\n\n\n<h3 class=\"wp-block-heading\">Password Attacks<\/h3>\n\n\n\n<ul class=\"wp-block-list\">\n<li>Brute Force<\/li>\n\n\n\n<li>Password Spraying<\/li>\n\n\n\n<li>Credential Stuffing<\/li>\n<\/ul>\n\n\n\n<h3 class=\"wp-block-heading\">MFA Testing<\/h3>\n\n\n\n<ul class=\"wp-block-list\">\n<li>MFA Bypass<\/li>\n\n\n\n<li>Race Condition<\/li>\n\n\n\n<li>OTP Replay<\/li>\n<\/ul>\n\n\n\n<h3 class=\"wp-block-heading\">Session Fixation<\/h3>\n\n\n\n<h3 class=\"wp-block-heading\">Remember-Me Token Analysis<\/h3>\n\n\n\n<h3 class=\"wp-block-heading\">JWT Weaknesses<\/h3>\n\n\n\n<ul class=\"wp-block-list\">\n<li>alg=none<\/li>\n\n\n\n<li>Key Confusion<\/li>\n\n\n\n<li>Expiration Bypass<\/li>\n<\/ul>\n\n\n\n<hr class=\"wp-block-separator has-alpha-channel-opacity\"\/>\n\n\n\n<h1 class=\"wp-block-heading\">Authorization Testing<\/h1>\n\n\n\n<p class=\"wp-block-paragraph\">\u0645\u0647\u0645\u200c\u062a\u0631\u06cc\u0646 \u0628\u062e\u0634 \u062a\u0633\u062a \u0646\u0641\u0648\u0630 \u0645\u062f\u0631\u0646<\/p>\n\n\n\n<h2 class=\"wp-block-heading\">Vertical Privilege Escalation<\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">\u062f\u0633\u062a\u0631\u0633\u06cc \u06a9\u0627\u0631\u0628\u0631 \u0639\u0627\u062f\u06cc \u0628\u0647 \u0627\u0645\u06a9\u0627\u0646\u0627\u062a \u0645\u062f\u06cc\u0631<\/p>\n\n\n\n<h2 class=\"wp-block-heading\">Horizontal Privilege Escalation<\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">\u062f\u0633\u062a\u0631\u0633\u06cc \u0628\u0647 \u0627\u0637\u0644\u0627\u0639\u0627\u062a \u0633\u0627\u06cc\u0631 \u06a9\u0627\u0631\u0628\u0631\u0627\u0646<\/p>\n\n\n\n<h2 class=\"wp-block-heading\">IDOR<\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">\u0646\u0645\u0648\u0646\u0647:<\/p>\n\n\n\n<pre class=\"wp-block-code\"><code>GET \/api\/invoices\/532<\/code><\/pre>\n\n\n\n<p class=\"wp-block-paragraph\">\u062a\u063a\u06cc\u06cc\u0631 \u0628\u0647:<\/p>\n\n\n\n<pre class=\"wp-block-code\"><code>GET \/api\/invoices\/533<\/code><\/pre>\n\n\n\n<p class=\"wp-block-paragraph\">\u0648 \u062f\u0633\u062a\u0631\u0633\u06cc \u0628\u0647 \u062f\u0627\u062f\u0647\u200c\u0647\u0627\u06cc \u062f\u06cc\u06af\u0631\u0627\u0646.<\/p>\n\n\n\n<hr class=\"wp-block-separator has-alpha-channel-opacity\"\/>\n\n\n\n<h1 class=\"wp-block-heading\">Session Management Testing<\/h1>\n\n\n\n<p class=\"wp-block-paragraph\">\u0628\u0631\u0631\u0633\u06cc:<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li>Session Hijacking<\/li>\n\n\n\n<li>Session Prediction<\/li>\n\n\n\n<li>Session Fixation<\/li>\n\n\n\n<li>Cookie Security<\/li>\n\n\n\n<li>SameSite<\/li>\n\n\n\n<li>HttpOnly<\/li>\n\n\n\n<li>Secure Flag<\/li>\n<\/ul>\n\n\n\n<hr class=\"wp-block-separator has-alpha-channel-opacity\"\/>\n\n\n\n<h1 class=\"wp-block-heading\">Input Validation Testing<\/h1>\n\n\n\n<h2 class=\"wp-block-heading\">SQL Injection<\/h2>\n\n\n\n<ul class=\"wp-block-list\">\n<li>Union Based<\/li>\n\n\n\n<li>Error Based<\/li>\n\n\n\n<li>Blind SQLi<\/li>\n\n\n\n<li>Time Based<\/li>\n\n\n\n<li>Second Order SQLi<\/li>\n<\/ul>\n\n\n\n<p class=\"wp-block-paragraph\">\u0627\u0628\u0632\u0627\u0631\u0647\u0627:<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li>Sqlmap<\/li>\n\n\n\n<li>Burp Intruder<\/li>\n<\/ul>\n\n\n\n<hr class=\"wp-block-separator has-alpha-channel-opacity\"\/>\n\n\n\n<h2 class=\"wp-block-heading\">NoSQL Injection<\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">MongoDB<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">\u0646\u0645\u0648\u0646\u0647:<\/p>\n\n\n\n<pre class=\"wp-block-code\"><code>{\n \"username\":{\"$ne\":null},\n \"password\":{\"$ne\":null}\n}<\/code><\/pre>\n\n\n\n<hr class=\"wp-block-separator has-alpha-channel-opacity\"\/>\n\n\n\n<h2 class=\"wp-block-heading\">Command Injection<\/h2>\n\n\n\n<pre class=\"wp-block-code\"><code>ping 8.8.8.8 &amp;&amp; whoami<\/code><\/pre>\n\n\n\n<hr class=\"wp-block-separator has-alpha-channel-opacity\"\/>\n\n\n\n<h2 class=\"wp-block-heading\">SSTI<\/h2>\n\n\n\n<ul class=\"wp-block-list\">\n<li>Jinja2<\/li>\n\n\n\n<li>Twig<\/li>\n\n\n\n<li>Freemarker<\/li>\n\n\n\n<li>Velocity<\/li>\n<\/ul>\n\n\n\n<p class=\"wp-block-paragraph\">\u0646\u0645\u0648\u0646\u0647:<\/p>\n\n\n\n<pre class=\"wp-block-code\"><code>{{7*7}}<\/code><\/pre>\n\n\n\n<hr class=\"wp-block-separator has-alpha-channel-opacity\"\/>\n\n\n\n<h2 class=\"wp-block-heading\">LDAP Injection<\/h2>\n\n\n\n<h2 class=\"wp-block-heading\">XPath Injection<\/h2>\n\n\n\n<h2 class=\"wp-block-heading\">XXE<\/h2>\n\n\n\n<ul class=\"wp-block-list\">\n<li>File Disclosure<\/li>\n\n\n\n<li>SSRF<\/li>\n\n\n\n<li>RCE<\/li>\n<\/ul>\n\n\n\n<hr class=\"wp-block-separator has-alpha-channel-opacity\"\/>\n\n\n\n<h1 class=\"wp-block-heading\">Cross Site Scripting<\/h1>\n\n\n\n<h3 class=\"wp-block-heading\">Reflected XSS<\/h3>\n\n\n\n<h3 class=\"wp-block-heading\">Stored XSS<\/h3>\n\n\n\n<h3 class=\"wp-block-heading\">DOM XSS<\/h3>\n\n\n\n<h3 class=\"wp-block-heading\">Mutation XSS<\/h3>\n\n\n\n<h3 class=\"wp-block-heading\">Blind XSS<\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">\u0627\u0628\u0632\u0627\u0631\u0647\u0627:<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li>Burp Collaborator<\/li>\n\n\n\n<li>XSSHunter<\/li>\n<\/ul>\n\n\n\n<hr class=\"wp-block-separator has-alpha-channel-opacity\"\/>\n\n\n\n<h1 class=\"wp-block-heading\">CSRF<\/h1>\n\n\n\n<p class=\"wp-block-paragraph\">\u0628\u0631\u0631\u0633\u06cc:<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li>Token Validation<\/li>\n\n\n\n<li>SameSite Cookie<\/li>\n\n\n\n<li>Origin Header<\/li>\n<\/ul>\n\n\n\n<hr class=\"wp-block-separator has-alpha-channel-opacity\"\/>\n\n\n\n<h1 class=\"wp-block-heading\">File Upload Testing<\/h1>\n\n\n\n<ul class=\"wp-block-list\">\n<li>Double Extension<\/li>\n\n\n\n<li>MIME Type Bypass<\/li>\n\n\n\n<li>Polyglot Files<\/li>\n\n\n\n<li>SVG XSS<\/li>\n\n\n\n<li>Zip Slip<\/li>\n\n\n\n<li>ImageTragick<\/li>\n<\/ul>\n\n\n\n<hr class=\"wp-block-separator has-alpha-channel-opacity\"\/>\n\n\n\n<h1 class=\"wp-block-heading\">Path Traversal<\/h1>\n\n\n\n<p class=\"wp-block-paragraph\">\u0646\u0645\u0648\u0646\u0647:<\/p>\n\n\n\n<pre class=\"wp-block-code\"><code>..\/..\/..\/..\/etc\/passwd<\/code><\/pre>\n\n\n\n<hr class=\"wp-block-separator has-alpha-channel-opacity\"\/>\n\n\n\n<h1 class=\"wp-block-heading\">SSRF<\/h1>\n\n\n\n<p class=\"wp-block-paragraph\">\u06cc\u06a9\u06cc \u0627\u0632 \u062e\u0637\u0631\u0646\u0627\u06a9\u200c\u062a\u0631\u06cc\u0646 \u062d\u0645\u0644\u0627\u062a \u0645\u062f\u0631\u0646<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">\u0627\u0647\u062f\u0627\u0641:<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li>AWS Metadata<\/li>\n<\/ul>\n\n\n\n<pre class=\"wp-block-code\"><code>169.254.169.254<\/code><\/pre>\n\n\n\n<ul class=\"wp-block-list\">\n<li>Internal Services<\/li>\n\n\n\n<li>Redis<\/li>\n\n\n\n<li>Elasticsearch<\/li>\n<\/ul>\n\n\n\n<hr class=\"wp-block-separator has-alpha-channel-opacity\"\/>\n\n\n\n<h1 class=\"wp-block-heading\">Deserialization Vulnerabilities<\/h1>\n\n\n\n<p class=\"wp-block-paragraph\">Java<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">.NET<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">PHP<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Python Pickle<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">NodeJS<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">\u0645\u0646\u062c\u0631 \u0628\u0647:<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li>RCE<\/li>\n\n\n\n<li>Privilege Escalation<\/li>\n<\/ul>\n\n\n\n<hr class=\"wp-block-separator has-alpha-channel-opacity\"\/>\n\n\n\n<h1 class=\"wp-block-heading\">Business Logic Testing<\/h1>\n\n\n\n<p class=\"wp-block-paragraph\">\u0628\u062e\u0634 \u0645\u0648\u0631\u062f \u0639\u0644\u0627\u0642\u0647 \u0645\u0647\u0627\u062c\u0645\u0627\u0646 \u062d\u0631\u0641\u0647\u200c\u0627\u06cc<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">\u0645\u0648\u0627\u0631\u062f \u0628\u0631\u0631\u0633\u06cc:<\/p>\n\n\n\n<h3 class=\"wp-block-heading\">Coupon Abuse<\/h3>\n\n\n\n<h3 class=\"wp-block-heading\">Race Condition<\/h3>\n\n\n\n<h3 class=\"wp-block-heading\">Price Manipulation<\/h3>\n\n\n\n<h3 class=\"wp-block-heading\">Wallet Manipulation<\/h3>\n\n\n\n<h3 class=\"wp-block-heading\">Multiple Refund Attack<\/h3>\n\n\n\n<h3 class=\"wp-block-heading\">Workflow Bypass<\/h3>\n\n\n\n<h3 class=\"wp-block-heading\">Approval Process Bypass<\/h3>\n\n\n\n<h3 class=\"wp-block-heading\">Account Takeover Chains<\/h3>\n\n\n\n<hr class=\"wp-block-separator has-alpha-channel-opacity\"\/>\n\n\n\n<h1 class=\"wp-block-heading\">API Penetration Testing<\/h1>\n\n\n\n<p class=\"wp-block-paragraph\">\u0628\u0631 \u0627\u0633\u0627\u0633 OWASP API Top 10<\/p>\n\n\n\n<h2 class=\"wp-block-heading\">BOLA<\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">Broken Object Level Authorization<\/p>\n\n\n\n<h2 class=\"wp-block-heading\">BFLA<\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">Broken Function Level Authorization<\/p>\n\n\n\n<h2 class=\"wp-block-heading\">Excessive Data Exposure<\/h2>\n\n\n\n<h2 class=\"wp-block-heading\">Mass Assignment<\/h2>\n\n\n\n<h2 class=\"wp-block-heading\">Improper Inventory Management<\/h2>\n\n\n\n<h2 class=\"wp-block-heading\">Unsafe Consumption of APIs<\/h2>\n\n\n\n<h2 class=\"wp-block-heading\">SSRF Through APIs<\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">\u0627\u0628\u0632\u0627\u0631\u0647\u0627:<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li>Postman<\/li>\n\n\n\n<li>Burp Suite<\/li>\n\n\n\n<li>Caido<\/li>\n\n\n\n<li>Insomnia<\/li>\n<\/ul>\n\n\n\n<hr class=\"wp-block-separator has-alpha-channel-opacity\"\/>\n\n\n\n<h1 class=\"wp-block-heading\">Cryptography Testing<\/h1>\n\n\n\n<p class=\"wp-block-paragraph\">\u0628\u0631\u0631\u0633\u06cc:<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li>TLS Configuration<\/li>\n\n\n\n<li>Weak Cipher<\/li>\n\n\n\n<li>MD5<\/li>\n\n\n\n<li>SHA1<\/li>\n\n\n\n<li>ECB Mode<\/li>\n\n\n\n<li>Hardcoded Keys<\/li>\n\n\n\n<li>JWT Secrets<\/li>\n<\/ul>\n\n\n\n<p class=\"wp-block-paragraph\">\u0627\u0628\u0632\u0627\u0631\u0647\u0627:<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li>SSL Labs<\/li>\n\n\n\n<li>TestSSL<\/li>\n<\/ul>\n\n\n\n<hr class=\"wp-block-separator has-alpha-channel-opacity\"\/>\n\n\n\n<h1 class=\"wp-block-heading\">Client Side Testing<\/h1>\n\n\n\n<ul class=\"wp-block-list\">\n<li>CSP<\/li>\n\n\n\n<li>Clickjacking<\/li>\n\n\n\n<li>CORS<\/li>\n\n\n\n<li>Local Storage Leakage<\/li>\n\n\n\n<li>DOM Clobbering<\/li>\n<\/ul>\n\n\n\n<hr class=\"wp-block-separator has-alpha-channel-opacity\"\/>\n\n\n\n<h1 class=\"wp-block-heading\">Error Handling<\/h1>\n\n\n\n<p class=\"wp-block-paragraph\">\u0628\u0631\u0631\u0633\u06cc:<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li>Stack Trace Leakage<\/li>\n\n\n\n<li>Debug Endpoint<\/li>\n\n\n\n<li>Verbose Error<\/li>\n<\/ul>\n\n\n\n<hr class=\"wp-block-separator has-alpha-channel-opacity\"\/>\n\n\n\n<h1 class=\"wp-block-heading\">Security Misconfiguration<\/h1>\n\n\n\n<ul class=\"wp-block-list\">\n<li>Default Credentials<\/li>\n\n\n\n<li>Directory Listing<\/li>\n\n\n\n<li>Admin Panels<\/li>\n\n\n\n<li>Open S3 Bucket<\/li>\n\n\n\n<li>Backup Files<\/li>\n<\/ul>\n\n\n\n<hr class=\"wp-block-separator has-alpha-channel-opacity\"\/>\n\n\n\n<h1 class=\"wp-block-heading\">Web Cache Poisoning<\/h1>\n\n\n\n<p class=\"wp-block-paragraph\">\u062d\u0645\u0644\u0627\u062a \u062c\u062f\u06cc\u062f \u0644\u0627\u06cc\u0647 CDN<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">\u0628\u0631\u0631\u0633\u06cc:<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li>Host Header Injection<\/li>\n\n\n\n<li>Cache Key Manipulation<\/li>\n<\/ul>\n\n\n\n<hr class=\"wp-block-separator has-alpha-channel-opacity\"\/>\n\n\n\n<h1 class=\"wp-block-heading\">HTTP Request Smuggling<\/h1>\n\n\n\n<p class=\"wp-block-paragraph\">CL.TE<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">TE.CL<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">HTTP\/2 Desync<\/p>\n\n\n\n<hr class=\"wp-block-separator has-alpha-channel-opacity\"\/>\n\n\n\n<h1 class=\"wp-block-heading\">WebSocket Security<\/h1>\n\n\n\n<p class=\"wp-block-paragraph\">\u0628\u0631\u0631\u0633\u06cc:<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li>Authentication<\/li>\n\n\n\n<li>Message Tampering<\/li>\n\n\n\n<li>Origin Validation<\/li>\n<\/ul>\n\n\n\n<hr class=\"wp-block-separator has-alpha-channel-opacity\"\/>\n\n\n\n<h1 class=\"wp-block-heading\">GraphQL Security Testing<\/h1>\n\n\n\n<ul class=\"wp-block-list\">\n<li>Introspection Abuse<\/li>\n\n\n\n<li>Depth Attack<\/li>\n\n\n\n<li>Alias Attack<\/li>\n\n\n\n<li>Batch Query Attack<\/li>\n<\/ul>\n\n\n\n<hr class=\"wp-block-separator has-alpha-channel-opacity\"\/>\n\n\n\n<h1 class=\"wp-block-heading\">Supply Chain Security<\/h1>\n\n\n\n<p class=\"wp-block-paragraph\">\u062a\u0647\u062f\u06cc\u062f\u06cc \u06a9\u0647 \u062f\u0631 \u0633\u0627\u0644\u200c\u0647\u0627\u06cc \u0627\u062e\u06cc\u0631 \u0627\u0647\u0645\u06cc\u062a \u0632\u06cc\u0627\u062f\u06cc \u067e\u06cc\u062f\u0627 \u06a9\u0631\u062f\u0647 \u0627\u0633\u062a.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">\u0628\u0631\u0631\u0633\u06cc:<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li>Dependency Confusion<\/li>\n\n\n\n<li>Typosquatting<\/li>\n\n\n\n<li>Malicious Package<\/li>\n\n\n\n<li>Build Pipeline Compromise<\/li>\n<\/ul>\n\n\n\n<p class=\"wp-block-paragraph\">\u0627\u0628\u0632\u0627\u0631\u0647\u0627:<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li>Trivy<\/li>\n\n\n\n<li>Snyk<\/li>\n\n\n\n<li>Syft<\/li>\n\n\n\n<li>Grype<\/li>\n<\/ul>\n\n\n\n<hr class=\"wp-block-separator has-alpha-channel-opacity\"\/>\n\n\n\n<h1 class=\"wp-block-heading\">Secrets Hunting<\/h1>\n\n\n\n<p class=\"wp-block-paragraph\">\u06a9\u0634\u0641:<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li>API Keys<\/li>\n\n\n\n<li>JWT Secret<\/li>\n\n\n\n<li>AWS Keys<\/li>\n<\/ul>\n\n\n\n<p class=\"wp-block-paragraph\">\u0627\u0628\u0632\u0627\u0631\u0647\u0627:<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li>Gitleaks<\/li>\n\n\n\n<li>TruffleHog<\/li>\n<\/ul>\n\n\n\n<hr class=\"wp-block-separator has-alpha-channel-opacity\"\/>\n\n\n\n<h1 class=\"wp-block-heading\">\u062a\u0633\u062a Race Condition<\/h1>\n\n\n\n<p class=\"wp-block-paragraph\">\u0627\u0628\u0632\u0627\u0631\u0647\u0627:<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li>Turbo Intruder<\/li>\n\n\n\n<li>Parallel Request<\/li>\n<\/ul>\n\n\n\n<p class=\"wp-block-paragraph\">\u0645\u0648\u0627\u0631\u062f:<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li>\u062f\u0648\u0628\u0627\u0631 \u067e\u0631\u062f\u0627\u062e\u062a<\/li>\n\n\n\n<li>\u062f\u0648\u0628\u0627\u0631 \u0628\u0631\u062f\u0627\u0634\u062a<\/li>\n\n\n\n<li>\u0686\u0646\u062f \u0633\u0641\u0627\u0631\u0634 \u0647\u0645\u0632\u0645\u0627\u0646<\/li>\n<\/ul>\n\n\n\n<hr class=\"wp-block-separator has-alpha-channel-opacity\"\/>\n\n\n\n<h1 class=\"wp-block-heading\">\u0627\u0631\u0632\u06cc\u0627\u0628\u06cc \u0632\u0646\u062c\u06cc\u0631\u0647 \u062d\u0645\u0644\u0647<\/h1>\n\n\n\n<p class=\"wp-block-paragraph\">Pentester \u062d\u0631\u0641\u0647\u200c\u0627\u06cc \u0628\u0647 \u062f\u0646\u0628\u0627\u0644 \u06cc\u06a9 \u0622\u0633\u06cc\u0628\u200c\u067e\u0630\u06cc\u0631\u06cc \u0645\u0646\u0641\u0631\u062f \u0646\u06cc\u0633\u062a.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">\u0645\u062b\u0627\u0644:<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">User Enumeration<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">\u2193<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Password Reset Weakness<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">\u2193<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">JWT Weakness<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">\u2193<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">IDOR<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">\u2193<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Privilege Escalation<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">\u2193<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Account Takeover<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">\u2193<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">RCE<\/p>\n\n\n\n<hr class=\"wp-block-separator has-alpha-channel-opacity\"\/>\n\n\n\n<h1 class=\"wp-block-heading\">\u0627\u0628\u0632\u0627\u0631\u0647\u0627\u06cc \u0645\u0648\u0631\u062f \u0627\u0633\u062a\u0641\u0627\u062f\u0647 \u062f\u0631 \u0631\u0627\u062f\u0646\u062a<\/h1>\n\n\n\n<h3 class=\"wp-block-heading\">Burp Suite Professional<\/h3>\n\n\n\n<h3 class=\"wp-block-heading\">Nmap<\/h3>\n\n\n\n<h3 class=\"wp-block-heading\">Amass<\/h3>\n\n\n\n<h3 class=\"wp-block-heading\">Subfinder<\/h3>\n\n\n\n<h3 class=\"wp-block-heading\">Feroxbuster<\/h3>\n\n\n\n<h3 class=\"wp-block-heading\">Sqlmap<\/h3>\n\n\n\n<h3 class=\"wp-block-heading\">nuclei<\/h3>\n\n\n\n<h3 class=\"wp-block-heading\">ffuf<\/h3>\n\n\n\n<h3 class=\"wp-block-heading\">Caido<\/h3>\n\n\n\n<h3 class=\"wp-block-heading\">Postman<\/h3>\n\n\n\n<h3 class=\"wp-block-heading\">Trivy<\/h3>\n\n\n\n<h3 class=\"wp-block-heading\">Gitleaks<\/h3>\n\n\n\n<h3 class=\"wp-block-heading\">XSSHunter<\/h3>\n\n\n\n<h3 class=\"wp-block-heading\">OWASP ZAP<\/h3>\n\n\n\n<h3 class=\"wp-block-heading\">Metasploit<\/h3>\n\n\n\n<hr class=\"wp-block-separator has-alpha-channel-opacity\"\/>\n\n\n\n<h1 class=\"wp-block-heading\">\u062c\u0645\u0639\u200c\u0628\u0646\u062f\u06cc<\/h1>\n\n\n\n<p class=\"wp-block-paragraph\"><\/p>\n\n\n\n<p class=\"wp-block-paragraph\">\u062a\u0633\u062a \u0646\u0641\u0648\u0630 \u0645\u062f\u0631\u0646 \u062f\u06cc\u06af\u0631 \u0645\u062d\u062f\u0648\u062f \u0628\u0647 OWASP Top 10 \u0646\u06cc\u0633\u062a. \u0645\u0647\u0627\u062c\u0645\u0627\u0646 \u0627\u0645\u0631\u0648\u0632\u06cc \u0628\u06cc\u0634\u062a\u0631 \u0627\u0632 \u0622\u0633\u06cc\u0628\u200c\u067e\u0630\u06cc\u0631\u06cc\u200c\u0647\u0627\u06cc \u0645\u0646\u0637\u0642\u06cc\u060c API\u0647\u0627\u060c \u0632\u0646\u062c\u06cc\u0631\u0647 \u062a\u0623\u0645\u06cc\u0646 \u0646\u0631\u0645\u200c\u0627\u0641\u0632\u0627\u0631 \u0648 \u062a\u0631\u06a9\u06cc\u0628 \u0686\u0646\u062f \u0636\u0639\u0641 \u0627\u0645\u0646\u06cc\u062a\u06cc \u0628\u0631\u0627\u06cc \u0631\u0633\u06cc\u062f\u0646 \u0628\u0647 \u0646\u0641\u0648\u0630 \u0646\u0647\u0627\u06cc\u06cc \u0627\u0633\u062a\u0641\u0627\u062f\u0647 \u0645\u06cc\u200c\u06a9\u0646\u0646\u062f.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">\u062f\u0631 \u0631\u0627\u062f\u0646\u062a\u060c \u0627\u0631\u0632\u06cc\u0627\u0628\u06cc \u0627\u0645\u0646\u06cc\u062a \u0646\u0631\u0645\u200c\u0627\u0641\u0632\u0627\u0631\u0647\u0627\u06cc \u062a\u062d\u062a \u0648\u0628 \u0628\u0631 \u0627\u0633\u0627\u0633 \u0627\u0633\u062a\u0627\u0646\u062f\u0627\u0631\u062f\u0647\u0627\u06cc OWASP WSTG\u060c ASVS \u0648 \u0645\u062a\u062f\u0648\u0644\u0648\u0698\u06cc\u200c\u0647\u0627\u06cc \u062d\u0631\u0641\u0647\u200c\u0627\u06cc VAPT \u0627\u0646\u062c\u0627\u0645 \u0645\u06cc\u200c\u0634\u0648\u062f \u062a\u0627 \u0639\u0644\u0627\u0648\u0647 \u0628\u0631 \u06a9\u0634\u0641 \u0622\u0633\u06cc\u0628\u200c\u067e\u0630\u06cc\u0631\u06cc\u200c\u0647\u0627\u06cc \u06a9\u0644\u0627\u0633\u06cc\u06a9\u060c \u0636\u0639\u0641\u200c\u0647\u0627\u06cc \u0645\u0639\u0645\u0627\u0631\u06cc \u0648 \u0633\u0646\u0627\u0631\u06cc\u0648\u0647\u0627\u06cc \u067e\u06cc\u0686\u06cc\u062f\u0647 \u0633\u0648\u0621\u0627\u0633\u062a\u0641\u0627\u062f\u0647 \u0646\u06cc\u0632 \u0634\u0646\u0627\u0633\u0627\u06cc\u06cc \u0634\u0648\u0646\u062f.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">\u0627\u0645\u0646\u06cc\u062a \u0648\u0627\u0642\u0639\u06cc \u0632\u0645\u0627\u0646\u06cc \u062d\u0627\u0635\u0644 \u0645\u06cc\u200c\u0634\u0648\u062f \u06a9\u0647 \u062a\u0633\u062a \u0646\u0641\u0648\u0630 \u0628\u0647 \u0639\u0646\u0648\u0627\u0646 \u0628\u062e\u0634\u06cc \u0627\u0632 \u0686\u0631\u062e\u0647 DevSecOps \u0648 \u0641\u0631\u0627\u06cc\u0646\u062f \u062a\u0648\u0633\u0639\u0647 \u0646\u0631\u0645\u200c\u0627\u0641\u0632\u0627\u0631 \u062f\u0631 \u0646\u0638\u0631 \u06af\u0631\u0641\u062a\u0647 \u0634\u0648\u062f\u060c \u0646\u0647 \u06cc\u06a9 \u0641\u0639\u0627\u0644\u06cc\u062a \u0645\u0642\u0637\u0639\u06cc \u067e\u0633 \u0627\u0632 \u0627\u0633\u062a\u0642\u0631\u0627\u0631 \u0633\u06cc\u0633\u062a\u0645.<\/p>\n","protected":false},"excerpt":{"rendered":"<p>\u0631 \u0628\u0633\u06cc\u0627\u0631\u06cc \u0627\u0632 \u0633\u0627\u0632\u0645\u0627\u0646\u200c\u0647\u0627\u060c \u0627\u0645\u0646\u06cc\u062a \u0646\u0631\u0645\u200c\u0627\u0641\u0632\u0627\u0631 \u0628\u0647 \u0627\u062c\u0631\u0627\u06cc \u0686\u0646\u062f \u0627\u0633\u06a9\u0646 \u0627\u062a\u0648\u0645\u0627\u062a\u06cc\u06a9 \u0628\u0627 \u0627\u0628\u0632\u0627\u0631\u0647\u0627\u06cc\u06cc \u0645\u0627\u0646\u0646\u062f Burp Suite \u06cc\u0627 Acunetix \u0645\u062d\u062f\u0648\u062f \u0645\u06cc\u200c\u0634\u0648\u062f\u060c \u062f\u0631 \u062d\u0627\u0644\u06cc \u06a9\u0647 \u062d\u0645\u0644\u0627\u062a \u0648\u0627\u0642\u0639\u06cc \u0645\u0647\u0627\u062c\u0645\u0627\u0646 \u0628\u0633\u06cc\u0627\u0631 \u067e\u06cc\u0686\u06cc\u062f\u0647\u200c\u062a\u0631 \u0627\u0632 \u0622\u0633\u06cc\u0628\u200c\u067e\u0630\u06cc\u0631\u06cc\u200c\u0647\u0627\u06cc \u0634\u0646\u0627\u062e\u062a\u0647\u200c\u0634\u062f\u0647 OWASP Top 10 \u0647\u0633\u062a\u0646\u062f. \u062f\u0631 \u0634\u0631\u06a9\u062a \u0628\u0631\u0646\u0627\u0645\u0647\u200c\u0646\u0648\u06cc\u0633\u06cc \u0631\u0627\u062f\u0646\u062a\u060c \u062a\u0633\u062a \u0646\u0641\u0648\u0630 \u0635\u0631\u0641\u0627\u064b \u0628\u0647 \u0645\u0639\u0646\u06cc \u06cc\u0627\u0641\u062a\u0646 SQL Injection \u06cc\u0627 XSS \u0646\u06cc\u0633\u062a\u060c \u0628\u0644\u06a9\u0647 \u06cc\u06a9 \u0641\u0631\u0627\u06cc\u0646\u062f \u0686\u0646\u062f\u0645\u0631\u062d\u0644\u0647\u200c\u0627\u06cc \u0645\u0628\u062a\u0646\u06cc &hellip;<\/p>\n","protected":false},"author":1,"featured_media":487,"comment_status":"closed","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[320],"tags":[423],"class_list":["post-486","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-320","tag-423"],"_links":{"self":[{"href":"https:\/\/blog.radnetco.com\/index.php?rest_route=\/wp\/v2\/posts\/486","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/blog.radnetco.com\/index.php?rest_route=\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/blog.radnetco.com\/index.php?rest_route=\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/blog.radnetco.com\/index.php?rest_route=\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/blog.radnetco.com\/index.php?rest_route=%2Fwp%2Fv2%2Fcomments&post=486"}],"version-history":[{"count":1,"href":"https:\/\/blog.radnetco.com\/index.php?rest_route=\/wp\/v2\/posts\/486\/revisions"}],"predecessor-version":[{"id":489,"href":"https:\/\/blog.radnetco.com\/index.php?rest_route=\/wp\/v2\/posts\/486\/revisions\/489"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/blog.radnetco.com\/index.php?rest_route=\/wp\/v2\/media\/487"}],"wp:attachment":[{"href":"https:\/\/blog.radnetco.com\/index.php?rest_route=%2Fwp%2Fv2%2Fmedia&parent=486"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/blog.radnetco.com\/index.php?rest_route=%2Fwp%2Fv2%2Fcategories&post=486"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/blog.radnetco.com\/index.php?rest_route=%2Fwp%2Fv2%2Ftags&post=486"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}