Skip to content

Latest commit

 

History

4 Commits

Folders and files

NameName
Last commit message
Last commit date
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 

Repository files navigation

🌐 Web Application Penetration Testing

A complete, methodology-driven web application security testing reference — aligned with OWASP Top 10:2025.
Built from real lab experience across HackTheBox, TryHackMe, and OffSec Proving Grounds.

Updated OWASP License

📋 OWASP Top 10:2025 — What's New

One new category entered the 2025 list (Mishandling of Exceptional Conditions), and SSRF — previously its own category in 2021 — has been merged into Broken Access Control.

# 2025 Category 2021 Position Change
A01 Broken Access Control A01 SSRF merged in (was A10:2021)
A02 Security Misconfiguration A05 Moved up
A03 Software Supply Chain Failures A06 Expanded from "Vulnerable and Outdated Components"
A04 Cryptographic Failures A02 Moved down
A05 Injection A03 Moved down
A06 Insecure Design A04 Moved down
A07 Authentication Failures A07 Renamed (was "Identification and Authentication Failures")
A08 Software or Data Integrity Failures A08 Unchanged (minor rename)
A09 Security Logging and Alerting Failures A09 Renamed (alerting emphasis, was "...and Monitoring Failures")
A10 Mishandling of Exceptional Conditions — NEW in 2025

SSRF (was A10:2021) is now formally part of A01:2025 — Broken Access Control. There is no standalone "Client-Side / XSS" category in 2025 — XSS is covered under A05:2025 Injection.


📖 Contents

# Section OWASP Coverage
00 🗺️ Methodology & Workflow Full engagement workflow
01 🔍 Recon & Enumeration Pre-exploitation recon
02 🔐 Authentication Testing A07:2025
03 🚪 Broken Access Control A01:2025 — IDOR, SSRF, CORS
04 💉 Injection Attacks A05:2025 — SQLi, CMDi, SSTI, XXE
05 🖥️ XSS & Client-Side Attacks A05:2025 (Injection)
06 ⚙️ Security Misconfiguration A02:2025
07 🔒 Cryptographic Failures A04:2025
08 🏗️ Insecure Design & Logic Flaws A06:2025
09 📦 Software Supply Chain A03:2025
10 ✅ Software & Data Integrity A08:2025
11 📋 Logging & Alerting Failures A09:2025
12 ⚠️ Exceptional Conditions A10:2025 — NEW
13 🔌 API Penetration Testing REST, GraphQL, BOLA
14 📁 File Upload Attacks Upload bypass, webshells
15 🛠️ Tools & Wordlists Burp, ffuf, sqlmap, nuclei
16 📝 Report Templates Finding format, CVSS guide

🗺️ Web App Attack Roadmap

TARGET URL
    │
    ├─ 01. RECON ──────────── whatweb → headers → tech stack → subdomains
    │
    ├─ 02. ENUMERATE ─────── ffuf/gobuster → directories → files → params
    │       │
    │       ├─ JS files ──── endpoints → API routes → hardcoded secrets
    │       ├─ Robots.txt ── hidden paths
    │       └─ Source code ─ comments → credentials → internal IPs
    │
    ├─ 03. AUTHENTICATE ──── default creds → brute force → MFA bypass
    │
    ├─ 04. ATTACK SURFACE ──────────────────────────────────────────────
    │       │
    │       ├─ INPUT FIELDS
    │       │    ├─ SQLi ──────── ' → UNION → sqlmap
    │       │    ├─ SSTI ──────── {{7*7}} → RCE
    │       │    ├─ XSS ───────── <script> → stored / reflected / DOM
    │       │    ├─ CMDi ─────── ; whoami → reverse shell
    │       │    ├─ XXE ────────── external entity → file read / SSRF
    │       │    └─ LFI/RFI ──── ../etc/passwd → log poison → RCE
    │       │
    │       ├─ ACCESS CONTROL
    │       │    ├─ IDOR ──────── change id=1 → id=2
    │       │    ├─ SSRF ──────── fetch internal → cloud metadata
    │       │    ├─ CORS ──────── reflect origin → steal credentials
    │       │    └─ JWT ─────────  none alg → HS256 confusion → brute secret
    │       │
    │       ├─ FILE UPLOAD
    │       │    ├─ Extension bypass → .php disguised as .jpg
    │       │    ├─ MIME bypass → Content-Type manipulation
    │       │    └─ Webshell upload → RCE
    │       │
    │       └─ API
    │            ├─ BOLA ──────── user A accessing user B objects
    │            ├─ Mass assign ─ inject role=admin in register
    │            └─ GraphQL ───── introspection → schema dump → IDOR
    │
    └─ 05. POST-EXPLOITATION
            ├─ Extract credentials from DB
            ├─ Read sensitive config files
            ├─ Pivot to internal network (SSRF → internal)
            └─ Escalate to server OS (webshell → reverse shell)

⚡ Quick Reference — Common Payloads

Detection Probes (Test These First)

SQLi:          '  OR 1=1--  AND SLEEP(5)--
XSS:           <script>alert(1)</script>  "><img src=x onerror=alert(1)>
SSTI:          {{7*7}}  ${7*7}  <%= 7*7 %>
CMDi:          ; id  | whoami  && id  `id`  $(id)
LFI:           ../etc/passwd  ....//....//etc/passwd
XXE:           <!DOCTYPE foo [<!ENTITY xxe SYSTEM "file:///etc/passwd">]>
Path Traversal: ../../../etc/passwd  ..%2F..%2Fetc%2Fpasswd
SSRF:          http://127.0.0.1/  http://169.254.169.254/

Burp Suite Quick Shortcuts

Ctrl+R   → Repeater
Ctrl+I   → Intruder
Ctrl+D   → Send to Decoder
Ctrl+U   → URL encode selection
Ctrl+H   → Search in response

📚 Reference Resources

Resource URL
OWASP Top 10:2025 https://owasp.org/Top10/2025/
PortSwigger Web Security Academy https://portswigger.net/web-security
PayloadsAllTheThings https://github.com/swisskyrepo/PayloadsAllTheThings
HackTricks Web https://book.hacktricks.xyz/pentesting-web
SecLists https://github.com/danielmiessler/SecLists
OWASP Testing Guide v4.2 https://owasp.org/www-project-web-security-testing-guide/

🔗 Related Repositories

Repo Description
active-directory-pentesting Full AD attack lifecycle — Kerberoasting to Domain Admin
penetration-testing-writeups 80+ OSCP-style machine walkthroughs
pentest-cheatsheet 2,600+ notes — full attack chain recon to domain compromise

⚠️ For authorized security testing and educational purposes only.

About

Complete web application penetration testing reference — OWASP Top 10:2025 aligned, covering injection, access control, API security, file upload attacks, and client-side exploits.

Topics

Resources

Stars

2 stars

Watchers

0 watching

Forks

Releases

Packages

Contributors