Nikto + OWASP ZAP Tutorial | Finding & Exploiting Web Vulnerabilities (Week 4 Assignment)
Автор: Practical Academy
Загружено: 2026-02-06
Просмотров: 17
Описание:
In Week 4 of my cybersecurity course, I performed automated and manual web application security testing using Nikto, OWASP ZAP, curl, and browser tools against DVWA and WebGoat labs.
This video walks through every step of the assignment:
• Running 3 different Nikto scans (basic, comprehensive, subdirectory)
• Passive + Active scanning with OWASP ZAP (spidering + full active attack)
• Exporting ZAP HTML report and analyzing alerts
• HTTP security header inspection (X-Frame-Options, HSTS, CSP, Server leakage)
• Manually verifying and exploiting 2+ vulnerabilities (XSS, directory listing, etc.)
• Creating the Week 4 Security Report with screenshots, findings, risk analysis & recommendations
Perfect for students in ethical hacking, web pentesting, or cybersecurity fundamentals courses (Security+, CEH, OSCP prep, CySA+, etc.).
#WebApplicationSecurity #OWASPZAP #Nikto #EthicalHacking #PenetrationTesting #CybersecurityLab #DVWA #WebGoat #XSS #SecurityHeaders
If you're doing the same assignment, drop your biggest challenge in the comments — I may do follow-up videos!
Legal note: This is for authorized lab/educational use only. Never test on systems you do not own or have explicit written permission to attack.
Повторяем попытку...
Доступные форматы для скачивания:
Скачать видео
-
Информация по загрузке: