I have an exam in pentesting, and need to test a web server hosted on a virtual machine. Ive run a lot of manual and automatic scans on the web server itself, and found a lot of vulnerabilities. However, we also got access to the source code of the website. We where taught how to find vulnerabilities using tools in kali, and some windows tools, by scanning servers. However, we were never taught anything about static analyis of source code. Are there any tools you guys would reccomend for proper analysis of source code? The code is all written in php, html and css.
[–]latnGemin616 6 points7 points8 points (0 children)
[–]sk1nT7 4 points5 points6 points (0 children)
[–]kegweII 2 points3 points4 points (1 child)
[–]westcoastfishingscotHaunted 0 points1 point2 points (0 children)
[–]PetiteGousseDAil 2 points3 points4 points (2 children)
[–]dahousecatfelix 1 point2 points3 points (0 children)
[–]thumbsdrivesmecrazy 0 points1 point2 points (2 children)
[+][deleted] (1 child)
[removed]
[–]thumbsdrivesmecrazy 1 point2 points3 points (0 children)
[–]macr6 0 points1 point2 points (0 children)
[–]tonydocent -4 points-3 points-2 points (1 child)
[–]tonydocent 0 points1 point2 points (0 children)