A complete, methodology-driven web application security testing reference — aligned with OWASP Top 10:2025.
Built from real lab experience across HackTheBox, TryHackMe, and OffSec Proving Grounds.
One new category entered the 2025 list (Mishandling of Exceptional Conditions), and SSRF — previously its own category in 2021 — has been merged into Broken Access Control.
| # | 2025 Category | 2021 Position | Change |
|---|---|---|---|
| A01 | Broken Access Control | A01 | SSRF merged in (was A10:2021) |
| A02 | Security Misconfiguration | A05 | Moved up |
| A03 | Software Supply Chain Failures | A06 | Expanded from "Vulnerable and Outdated Components" |
| A04 | Cryptographic Failures | A02 | Moved down |
| A05 | Injection | A03 | Moved down |
| A06 | Insecure Design | A04 | Moved down |
| A07 | Authentication Failures | A07 | Renamed (was "Identification and Authentication Failures") |
| A08 | Software or Data Integrity Failures | A08 | Unchanged (minor rename) |
| A09 | Security Logging and Alerting Failures | A09 | Renamed (alerting emphasis, was "...and Monitoring Failures") |
| A10 | Mishandling of Exceptional Conditions | — | NEW in 2025 |
SSRF (was A10:2021) is now formally part of A01:2025 — Broken Access Control. There is no standalone "Client-Side / XSS" category in 2025 — XSS is covered under A05:2025 Injection.
| # | Section | OWASP Coverage |
|---|---|---|
| 00 | 🗺️ Methodology & Workflow | Full engagement workflow |
| 01 | 🔍 Recon & Enumeration | Pre-exploitation recon |
| 02 | 🔐 Authentication Testing | A07:2025 |
| 03 | 🚪 Broken Access Control | A01:2025 — IDOR, SSRF, CORS |
| 04 | 💉 Injection Attacks | A05:2025 — SQLi, CMDi, SSTI, XXE |
| 05 | 🖥️ XSS & Client-Side Attacks | A05:2025 (Injection) |
| 06 | ⚙️ Security Misconfiguration | A02:2025 |
| 07 | 🔒 Cryptographic Failures | A04:2025 |
| 08 | 🏗️ Insecure Design & Logic Flaws | A06:2025 |
| 09 | 📦 Software Supply Chain | A03:2025 |
| 10 | ✅ Software & Data Integrity | A08:2025 |
| 11 | 📋 Logging & Alerting Failures | A09:2025 |
| 12 | A10:2025 — NEW | |
| 13 | 🔌 API Penetration Testing | REST, GraphQL, BOLA |
| 14 | 📁 File Upload Attacks | Upload bypass, webshells |
| 15 | 🛠️ Tools & Wordlists | Burp, ffuf, sqlmap, nuclei |
| 16 | 📝 Report Templates | Finding format, CVSS guide |
TARGET URL
│
├─ 01. RECON ──────────── whatweb → headers → tech stack → subdomains
│
├─ 02. ENUMERATE ─────── ffuf/gobuster → directories → files → params
│ │
│ ├─ JS files ──── endpoints → API routes → hardcoded secrets
│ ├─ Robots.txt ── hidden paths
│ └─ Source code ─ comments → credentials → internal IPs
│
├─ 03. AUTHENTICATE ──── default creds → brute force → MFA bypass
│
├─ 04. ATTACK SURFACE ──────────────────────────────────────────────
│ │
│ ├─ INPUT FIELDS
│ │ ├─ SQLi ──────── ' → UNION → sqlmap
│ │ ├─ SSTI ──────── {{7*7}} → RCE
│ │ ├─ XSS ───────── <script> → stored / reflected / DOM
│ │ ├─ CMDi ─────── ; whoami → reverse shell
│ │ ├─ XXE ────────── external entity → file read / SSRF
│ │ └─ LFI/RFI ──── ../etc/passwd → log poison → RCE
│ │
│ ├─ ACCESS CONTROL
│ │ ├─ IDOR ──────── change id=1 → id=2
│ │ ├─ SSRF ──────── fetch internal → cloud metadata
│ │ ├─ CORS ──────── reflect origin → steal credentials
│ │ └─ JWT ───────── none alg → HS256 confusion → brute secret
│ │
│ ├─ FILE UPLOAD
│ │ ├─ Extension bypass → .php disguised as .jpg
│ │ ├─ MIME bypass → Content-Type manipulation
│ │ └─ Webshell upload → RCE
│ │
│ └─ API
│ ├─ BOLA ──────── user A accessing user B objects
│ ├─ Mass assign ─ inject role=admin in register
│ └─ GraphQL ───── introspection → schema dump → IDOR
│
└─ 05. POST-EXPLOITATION
├─ Extract credentials from DB
├─ Read sensitive config files
├─ Pivot to internal network (SSRF → internal)
└─ Escalate to server OS (webshell → reverse shell)
SQLi: ' OR 1=1-- AND SLEEP(5)--
XSS: <script>alert(1)</script> "><img src=x onerror=alert(1)>
SSTI: {{7*7}} ${7*7} <%= 7*7 %>
CMDi: ; id | whoami && id `id` $(id)
LFI: ../etc/passwd ....//....//etc/passwd
XXE: <!DOCTYPE foo [<!ENTITY xxe SYSTEM "file:///etc/passwd">]>
Path Traversal: ../../../etc/passwd ..%2F..%2Fetc%2Fpasswd
SSRF: http://127.0.0.1/ http://169.254.169.254/
Ctrl+R → Repeater
Ctrl+I → Intruder
Ctrl+D → Send to Decoder
Ctrl+U → URL encode selection
Ctrl+H → Search in response
| Resource | URL |
|---|---|
| OWASP Top 10:2025 | https://owasp.org/Top10/2025/ |
| PortSwigger Web Security Academy | https://portswigger.net/web-security |
| PayloadsAllTheThings | https://github.com/swisskyrepo/PayloadsAllTheThings |
| HackTricks Web | https://book.hacktricks.xyz/pentesting-web |
| SecLists | https://github.com/danielmiessler/SecLists |
| OWASP Testing Guide v4.2 | https://owasp.org/www-project-web-security-testing-guide/ |
| Repo | Description |
|---|---|
| active-directory-pentesting | Full AD attack lifecycle — Kerberoasting to Domain Admin |
| penetration-testing-writeups | 80+ OSCP-style machine walkthroughs |
| pentest-cheatsheet | 2,600+ notes — full attack chain recon to domain compromise |
⚠️ For authorized security testing and educational purposes only.