Web

Web application testing, built around the OWASP Top 10 and the flaws that actually come up on a test.

The OWASP Top 10

The ten categories of web risk, and the map for everything else here.

beginner

SQL injection (SQLi)

Untrusted input changing a database query. The classic injection flaw.

intermediate

Cross-Site Scripting (XSS)

Input that the browser runs as code. Reflected, stored and DOM-based.

intermediate

Broken Access Control & IDOR

Reaching data and actions that should be off-limits. The #1 web risk.

beginner

Authentication failures

Weak logins, resets and sessions — and how they get abused.

beginner

Cross-Site Request Forgery (CSRF)

Making a logged-in user’s browser act without their intent.

intermediate

Server-Side Request Forgery (SSRF)

Making the server fetch things it shouldn’t. OWASP A10.

intermediate

File upload flaws

The wrong file in the wrong place — classically a web shell.

intermediate

Command injection

Input reaching a system shell. SQLi’s cousin, aimed at the OS.

intermediate

Security misconfiguration

Defaults, verbose errors and doors left open. Often the quickest win.

beginner

← Back to the Padawan Path