{"id":1197,"date":"2021-03-02T20:44:39","date_gmt":"2021-03-02T20:44:39","guid":{"rendered":"https:\/\/dft.wiki\/?p=1197"},"modified":"2026-06-09T09:36:37","modified_gmt":"2026-06-09T13:36:37","slug":"web-app-penetration-testing","status":"publish","type":"post","link":"https:\/\/dft.wiki\/?p=1197","title":{"rendered":"Web App Pentesting Tools and Tips"},"content":{"rendered":"<p>Intercepting and manipulating traffic is a fundamental technique in web application penetration testing. It is used to discover vulnerabilities, analyze data flows, and test how applications respond to unusual or malicious inputs.<\/p>\n<p>Frameworks<\/p>\n<ul>\n<li><strong>OWASP ZAP<\/strong> [<a href=\"https:\/\/owasp.org\/www-project-zap\/\">Link<\/a>]\n<ul>\n<li>The Zed Attack Proxy (ZAP) claims to be the world&#8217;s most widely used web app scanner.<\/li>\n<li>It is part of the OWASP family of resources, so it is free and open source.<\/li>\n<\/ul>\n<\/li>\n<li><strong>Burp Suite<\/strong> [<a href=\"https:\/\/portswigger.net\/burp\/communitydownload\">Link<\/a>]\n<ul>\n<li>Arguably the most popular tool on this list. The Community Edition offers most features for free, but the throttling in the Intruder can make for a frustrating experience.<\/li>\n<li>Note that version 2 of the Community Edition no longer includes the Spider feature, though many other tools can fill that gap.<\/li>\n<\/ul>\n<\/li>\n<li><strong>Caido<\/strong> [<a href=\"https:\/\/caido.io\/download\">Link<\/a>]\n<ul>\n<li>Available as both a graphical and command-line application. Its equivalent of Burp&#8217;s Intruder does not throttle.<\/li>\n<li>The CLI version also enables automation.<\/li>\n<\/ul>\n<\/li>\n<li><strong>MITMProxy<\/strong> [<a href=\"https:\/\/github.com\/mitmproxy\/mitmproxy\">Link<\/a>]\n<ul>\n<li>A free and open-source interactive HTTP\/HTTPS proxy. It terminates SSL\/TLS connections and uses a self-signed certificate for the client.<\/li>\n<li>Can be used via CLI or through a browser-based Web UI.<\/li>\n<li>For developers, it offers programmable APIs for full control over the proxy, data transformation, and more.<\/li>\n<\/ul>\n<\/li>\n<\/ul>\n<p>Extensions<\/p>\n<ul>\n<li><strong>FoxyProxy<\/strong> [<a href=\"https:\/\/addons.mozilla.org\/en-CA\/firefox\/addon\/foxyproxy-standard\/\">Link<\/a>]\n<ul>\n<li>An indispensable browser extension for quickly setting up, enabling, and disabling a proxy for traffic interception and analysis.<\/li>\n<\/ul>\n<\/li>\n<li><strong>ProxyChains<\/strong> [<a href=\"https:\/\/github.com\/haad\/proxychains\">Link<\/a>]\n<ul>\n<li>A CLI tool that wraps the execution of a client web application and forces its traffic through a chosen proxy or chain of proxies.<\/li>\n<\/ul>\n<\/li>\n<\/ul>\n<p>Assessments<\/p>\n<ul>\n<li><strong>OpenVAS Scanner<\/strong> [<a href=\"https:\/\/greenbone.github.io\/docs\/latest\/22.4\/container\/index.html\">Link<\/a>]\n<ul>\n<li>Can be easily installed on Kali or in a Docker container.<\/li>\n<li>OpenVAS Scanner is now part of the Greenbone Community Edition.<\/li>\n<\/ul>\n<\/li>\n<li><strong>Tenable Nessus Essentials<\/strong> [<a href=\"https:\/\/www.tenable.com\/products\/nessus\/nessus-essentials\">Link<\/a>]\n<ul>\n<li>A capable vulnerability scanner, free for non-commercial use with some limitations.<\/li>\n<\/ul>\n<\/li>\n<li><strong>NMAP Vuln Scripts<\/strong> [<a href=\"https:\/\/nmap.org\/nsedoc\/categories\/vuln.html\">Link<\/a>]\n<ul>\n<li>Using scripts, NMAP can programmatically assess applications for known vulnerabilities.<\/li>\n<\/ul>\n<\/li>\n<\/ul>\n<p>Vulnerable Apps and Labs<\/p>\n<ul>\n<li><strong>DVWA<\/strong> (Damn Vulnerable Web App) [<a href=\"https:\/\/dvwa.co.uk\/\">Link<\/a>]<\/li>\n<li><strong>Metasploitable VM<\/strong> [<a href=\"https:\/\/information.rapid7.com\/download-metasploitable-2017.html\">Link<\/a>]<\/li>\n<li><strong>OWASP Juice Shop<\/strong> [<a href=\"https:\/\/owasp.org\/www-project-juice-shop\/\">Link<\/a>]<\/li>\n<li><strong>VulnHub<\/strong> [<a href=\"https:\/\/www.vulnhub.com\/\">Link<\/a>]<\/li>\n<\/ul>\n","protected":false},"excerpt":{"rendered":"<p>Intercepting and manipulating traffic is a fundamental technique in web application penetration testing. It is [&hellip;]<\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"closed","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[9],"tags":[],"class_list":["post-1197","post","type-post","status-publish","format-standard","hentry","category-hacking"],"_links":{"self":[{"href":"https:\/\/dft.wiki\/index.php?rest_route=\/wp\/v2\/posts\/1197","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/dft.wiki\/index.php?rest_route=\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/dft.wiki\/index.php?rest_route=\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/dft.wiki\/index.php?rest_route=\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/dft.wiki\/index.php?rest_route=%2Fwp%2Fv2%2Fcomments&post=1197"}],"version-history":[{"count":8,"href":"https:\/\/dft.wiki\/index.php?rest_route=\/wp\/v2\/posts\/1197\/revisions"}],"predecessor-version":[{"id":5776,"href":"https:\/\/dft.wiki\/index.php?rest_route=\/wp\/v2\/posts\/1197\/revisions\/5776"}],"wp:attachment":[{"href":"https:\/\/dft.wiki\/index.php?rest_route=%2Fwp%2Fv2%2Fmedia&parent=1197"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/dft.wiki\/index.php?rest_route=%2Fwp%2Fv2%2Fcategories&post=1197"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/dft.wiki\/index.php?rest_route=%2Fwp%2Fv2%2Ftags&post=1197"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}