- Description
- Complete web application assessment · fingerprinting to shell.
- Best For
- Any target with a web service, web app CTF challenges, bug bounty prep.
- Strength
- Full coverage from passive recon to active exploitation with exact tool commands, wordlists, and bypass techniques.
in this domain 19 sections
- 01 Fingerprinting & Tech Stack Identification
- 02 Directory & File Enumeration
- 03 Manual Exploration with Burp Suite
- 04 File Upload Exploitation
- 05 Authentication Bypass
- 06 CMS-Specific Attacks
- 07 Endpoint Mapping (Python Crawler)
- 08 Server-Side Template Injection (SSTI)
- 09 Insecure Deserialization
- 10 XML External Entity (XXE)
- 11 JWT Attacks
- 12 NoSQL Injection
- 13 Decision Tree: Web Injection Point → What First?
- 14 SQL Injection (SQLi)
- 15 Cross-Site Scripting (XSS)
- 16 Broken Access Control / IDOR
- 17 Command Injection
- 18 File Inclusion (LFI / RFI)
- 19 Server-Side Request Forgery (SSRF)