Testlab
Preparation
Notes on techniques
TryHackMe rooms
Web client
Web server
XSS
SQLi
CSRF
Clickjacking
DOM-based vulns
CORS
XXE
SSRF
HTTP request smuggling
OS command injection
SSTI
Directory traversal
Access control vulnerabilities
Authentication
Websockets
Web cache poisoning
Insecure deserialisation
Information disclosure
Business logic vulnerabilities
HTTP Host header attacks
OAuth authentication
File upload vulnerabilities
JWT
Prototype pollution
root-me challenge: Directory traversal: Find the hidden section of the photo galery.
Directory traversal techniques (these writeups)
A Case of directory traversal
BlackHat US 2011 DotDotPwn directory traversal fuzzer
Etude de la faille CVE-2010-0013 Directory traversal vulnerability