OPSECTLAS you are here: Web
Web

Web Application PT

domain 19 sections

Description
Complete web application assessment · fingerprinting to shell.
Best For
Any target with a web service, web app CTF challenges, bug bounty prep.
Strength
Full coverage from passive recon to active exploitation with exact tool commands, wordlists, and bypass techniques.
in this domain 19 sections
  1. 01 Fingerprinting & Tech Stack Identification
  2. 02 Directory & File Enumeration
  3. 03 Manual Exploration with Burp Suite
  4. 04 File Upload Exploitation
  5. 05 Authentication Bypass
  6. 06 CMS-Specific Attacks
  7. 07 Endpoint Mapping (Python Crawler)
  8. 08 Server-Side Template Injection (SSTI)
  9. 09 Insecure Deserialization
  10. 10 XML External Entity (XXE)
  11. 11 JWT Attacks
  12. 12 NoSQL Injection
  13. 13 Decision Tree: Web Injection Point → What First?
  14. 14 SQL Injection (SQLi)
  15. 15 Cross-Site Scripting (XSS)
  16. 16 Broken Access Control / IDOR
  17. 17 Command Injection
  18. 18 File Inclusion (LFI / RFI)
  19. 19 Server-Side Request Forgery (SSRF)