Web
Web application testing, built around the OWASP Top 10 and the flaws that actually come up on a test.
The OWASP Top 10
The ten categories of web risk, and the map for everything else here.
beginnerSQL injection (SQLi)
Untrusted input changing a database query. The classic injection flaw.
intermediateCross-Site Scripting (XSS)
Input that the browser runs as code. Reflected, stored and DOM-based.
intermediateBroken Access Control & IDOR
Reaching data and actions that should be off-limits. The #1 web risk.
beginnerAuthentication failures
Weak logins, resets and sessions — and how they get abused.
beginnerCross-Site Request Forgery (CSRF)
Making a logged-in user’s browser act without their intent.
intermediateServer-Side Request Forgery (SSRF)
Making the server fetch things it shouldn’t. OWASP A10.
intermediateFile upload flaws
The wrong file in the wrong place — classically a web shell.
intermediateCommand injection
Input reaching a system shell. SQLi’s cousin, aimed at the OS.
intermediateSecurity misconfiguration
Defaults, verbose errors and doors left open. Often the quickest win.
beginner