Testlab
Preparation
Notes on techniques
TryHackMe rooms
Web client
Web server
XSS
SQLi
CSRF
Clickjacking
DOM-based vulns
CORS
XXE
SSRF
HTTP request smuggling
OS command injection
SSTI
Directory traversal
Access control vulnerabilities
Authentication
Websockets
Web cache poisoning
Insecure deserialisation
Information disclosure
Business logic vulnerabilities
HTTP Host header attacks
OAuth authentication
File upload vulnerabilities
JWT
Prototype pollution
Tackle challenges in determining and exploring vulnerabilities in web applications.
Cross-site scripting (XSS)
Open redirection
Cross-site request forgery (CSRF)
Insecure direct object references (IDOR)
SQL injection
Race conditions
Server-side request forgery (SSRF)
XML external entity (XXE) injection
HTTP Request smuggling
Template injection (SSTI)
Authentication vulnerabilities
Single-sign-on security (SSO)
Broken access control
Application logic errors
Websocket vulnerabilities
Remote code execution (RCE)
Same-origin policy (SOP)
File uploads
JSON web tokens attacks