Pentest Notes
Ctrlk
  • ๐Ÿ /home/x3m1Sec/.pt-notes
  • ๐Ÿ“Pentest Notes
    • ๐Ÿ”Information Gathering
    • ๐Ÿ“œProtocols and Services
    • ๐Ÿ•ธ๏ธWeb Applications
      • Web Attacks
      • Web Technologies
      • Fuzzing
    • ๐ŸชŸActive Directory Pentesting
    • ๐ŸงLinux Privilege Escalation
    • ๐ŸชŸWindows Privilege Escalation
    • ๐Ÿ›Bug Bounty Hunting
    • ๐Ÿ‘พUtilities, Scripts and Payloads
  • ๐ŸŽฎCTFs
  • ๐ŸŽ“Road to certification
  • ๐Ÿ“šResources
Powered by GitBook
On this page
  1. ๐Ÿ“Pentest Notes

๐Ÿ•ธ๏ธWeb Applications

Web Penetration Testing Methodologies

  • OWASP WSTG

    • OWASP WSTG Checklists

    • WSTG Checklist.MD

    • WSTG Checklist.xlsx

  • OWASP Top 10

  • OWASP CheatSheets

  • CWE List

  • CVSS v3 Calculator

  • Mitre ATT&CK matrix


Learning Resources

  1. https://portswigger.net/web-security

  2. https://book.hacktricks.xyz/network-services-pentesting/pentesting-web

  3. https://book.hacktricks.xyz/network-services-pentesting/pentesting-web/web-api-pentesting

  4. https://book.hacktricks.xyz/pentesting-web/web-vulnerabilities-methodology

PreviousNmap Commands for Port DiscoveryNextWeb Attacks

Last updated 8 months ago

  • Web Penetration Testing Methodologies
  • Learning Resources