Pentest Notes
search
⌘Ctrlk
Pentest Notes
  • 🏠/home/x3m1Sec/.pt-notes
  • 📝Pentest Notes
    • 🔍Information Gathering
    • 📜Protocols and Services
    • 🕸️Web Applications
      • Web Attacks
      • Web Technologies
      • Fuzzing
    • 🪟Active Directory Pentesting
    • 🐧Linux Privilege Escalation
    • 🪟Windows Privilege Escalation
    • 🐛Bug Bounty Hunting
    • 👾Utilities, Scripts and Payloads
  • 🎮CTFs
  • 🎓Road to certification
  • 📚Resources
gitbookPowered by GitBook
block-quoteOn this pagechevron-down
  1. 📝Pentest Notes

🕸️Web Applications

hashtag
Web Penetration Testing Methodologies

  • OWASP WSTGarrow-up-right

    • OWASP WSTG Checklistsarrow-up-right

    • WSTG Checklist.MDarrow-up-right

    • WSTG Checklist.xlsxarrow-up-right

  • OWASP Top 10arrow-up-right

  • OWASP CheatSheetsarrow-up-right

  • CWE Listarrow-up-right

  • CVSS v3 Calculatorarrow-up-right

  • Mitre ATT&CK matrixarrow-up-right


hashtag
Learning Resources

  1. https://portswigger.net/web-securityarrow-up-right

  2. https://book.hacktricks.xyz/network-services-pentesting/pentesting-webarrow-up-right

  3. https://book.hacktricks.xyz/network-services-pentesting/pentesting-web/web-api-pentestingarrow-up-right

  4. https://book.hacktricks.xyz/pentesting-web/web-vulnerabilities-methodologyarrow-up-right

PreviousNmap Commands for Port Discoverychevron-leftNextWeb Attackschevron-right

Last updated 10 months ago

  • Web Penetration Testing Methodologies
  • Learning Resources