A training course I wrote on Web Security, Exploit Development and Source Code Auditing In January 2009.
Keep in mind that this course has never been updated and has remained untouched ever since it was completed 13 years ago, it is also written in Italian.
Whilst not all the material is still relevant today (RFI, LFI log poisoning), most of the other vulnerability classes presented still are.
Publishing it as "Safe Keeping" for Memorabilia/Nostalgia days.
- Web Security
- Indice
- Prefaccia
- Vulnerabilità degli Include/Require
- Vulnerabilità di tipo SQL Injection
- Vulnerabilità legate al Logging
- Arbitrary File Upload
- Vulnerabilità di tipo Cross Site Scripting (XSS)
- Remote Command Execution (RCE)
- Vari Exploit e Spiegazioni
- Conclusione
The content is available in the Wiki page.