Pentest Notes
Ctrlk
  • 🏠/home/x3m1Sec/.pt-notes
  • 📝Pentest Notes
    • 🔍Information Gathering
    • 📜Protocols and Services
    • 🕸️Web Applications
      • Web Attacks
      • Web Technologies
      • Fuzzing
    • 🪟Active Directory Pentesting
    • 🐧Linux Privilege Escalation
    • 🪟Windows Privilege Escalation
    • 🐛Bug Bounty Hunting
    • 👾Utilities, Scripts and Payloads
  • 🎮CTFs
  • 🎓Road to certification
  • 📚Resources
Powered by GitBook
On this page
  • Web Penetration Testing Methodologies
  • Learning Resources
  1. 📝Pentest Notes

🕸️Web Applications

Web Penetration Testing Methodologies

  • OWASP WSTG

    • OWASP WSTG Checklists

    • WSTG Checklist.MD

    • WSTG Checklist.xlsx

  • OWASP Top 10

  • OWASP CheatSheets

  • CWE List

  • CVSS v3 Calculator

  • Mitre ATT&CK matrix


Learning Resources

  1. https://portswigger.net/web-security

  2. https://book.hacktricks.xyz/network-services-pentesting/pentesting-web

  3. https://book.hacktricks.xyz/network-services-pentesting/pentesting-web/web-api-pentesting

  4. https://book.hacktricks.xyz/pentesting-web/web-vulnerabilities-methodology

PreviousNmap Commands for Port DiscoveryNextWeb Attacks

Last updated 6 months ago