Testlab
Preparation
Notes on techniques
TryHackMe rooms
Web client
Web server
XSS
SQLi
CSRF
Clickjacking
DOM-based vulns
CORS
XXE
SSRF
HTTP request smuggling
OS command injection
SSTI
Directory traversal
Access control vulnerabilities
Authentication
Websockets
Web cache poisoning
Insecure deserialisation
Information disclosure
Business logic vulnerabilities
HTTP Host header attacks
OAuth authentication
File upload vulnerabilities
JWT
Prototype pollution
The fast, easy, and very affordable way to test hacking skills.
HTML disabled buttons
Javascript authentication
Javascript source
Javascript native code
XSS stored 1
CSP bypass inline
CSRF: zero protection