Testlab
Preparation
Notes on techniques
TryHackMe rooms
Web client
Web server
XSS
SQLi
CSRF
Clickjacking
DOM-based vulns
CORS
XXE
SSRF
HTTP request smuggling
OS command injection
SSTI
Directory traversal
Access control vulnerabilities
Authentication
Websockets
Web cache poisoning
Insecure deserialisation
Information disclosure
Business logic vulnerabilities
HTTP Host header attacks
OAuth authentication
File upload vulnerabilities
JWT
Prototype pollution
root-me challenge: Authentication v 0.01: Retrieve the administrator password.
username: admin'--
Injection SQL
Blackhat Europe 2009 - Advanced SQL injection whitepaper
Guide to PHP security : chapter 3 SQL injection
Blackhat US 2006 : SQL Injections by truncation
Manipulating SQL server using SQL injection