Roadmap
Web Pentester
Application testing from an honest methodology: scope, exploration, verification, impact and retest. Tooling supports the method rather than replacing it.
Prerequisites
- HTTP and headers fluency
- Reading HTML/JS without panic
- A lab application you own
Who it is for
Developers moving into appsec, junior testers, bug bounty newcomers
Outcome: You can plan a test, find and verify issues manually, describe impact in business terms, and confirm a fix.
Stages
Work them in order the first time. Ticking a stage only records your own progress, in this browser.
Stored in this browser only. No account, no sync.
Scope, rules of engagement and safety
What you may touch, how hard, when, and what to stop for immediately.
3 hoursLearn
- Written authorisation and asset lists
- Rate limits and data handling
- Stop conditions
Do
- Draft a one-page rules-of-engagement document for a lab target.
Exploration and mapping
Learn the application: features, roles, state changes, API surface.
1–2 weeksLearn
- Manual crawl before any automation
- Site map and parameter inventory
Do
- Produce a parameter inventory for one authenticated flow.
- Note every place the app changes server state.
Authentication and session handling
Login, token lifetime, password reset, MFA order — where logic flaws concentrate.
1 weekLearn
- Token formats and expiry
- Reset flow analysis
Do
- Map every endpoint reachable without a session and confirm intent with the owner.
ToolsBurp SuiteInput handling and injection
Where untrusted data is interpreted as code: SQL, commands, templates, queries.
1–2 weeksLearn
- Error-based vs blind indications
- Parameterised queries as the mitigation
Do
- Confirm one suspected parameter, then re-test after a fix.
- Write the exact evidence line a developer needs.
ToolsSQLMapAccess control
Object-level and function-level authorisation — the class automation cannot see.
1–2 weeksLearn
- Two-account matrix method
- Indirect reference patterns
Do
- Build a role/endpoint matrix for a lab app with two users.
ToolsBurp SuiteClient-side and browser behaviour
DOM sinks, CORS, cookie flags, caching and the origin model.
1 weekLearn
- Where browser policy is and is not enforced
- PostMessage and third-party script risk
Do
- Explain one CORS response to a developer without using the word 'vulnerable'.
ToolsffufVerification and false positives
Reproduce from a clean session, then prove the negative case too.
1 weekLearn
- Manual confirmation of scanner output
- Timing, caching and flakiness
Do
- Take five scanner findings and mark three as not reportable, with reasons.
ToolsNucleiReporting and retest
Impact language, reproduction steps, remediation that fits the codebase.
1 weekLearn
- Structure: condition, evidence, impact, fix
- Severity rationale over severity labels
Do
- Write one finding two ways: for a developer and for a manager.
Tools in this path
Each tool page carries installation steps, commands and the errors you will hit.