Skip to content

Roadmap

Web Pentester

Application testing from an honest methodology: scope, exploration, verification, impact and retest. Tooling supports the method rather than replacing it.

Intermediate → Advanced8 stages10–16 weeks

Prerequisites

  • HTTP and headers fluency
  • Reading HTML/JS without panic
  • A lab application you own

Who it is for

Developers moving into appsec, junior testers, bug bounty newcomers

Outcome: You can plan a test, find and verify issues manually, describe impact in business terms, and confirm a fix.

Stages

Work them in order the first time. Ticking a stage only records your own progress, in this browser.

Progress0 / 80%

Stored in this browser only. No account, no sync.

  1. Scope, rules of engagement and safety

    What you may touch, how hard, when, and what to stop for immediately.

    3 hours

    Learn

    • Written authorisation and asset lists
    • Rate limits and data handling
    • Stop conditions

    Do

    • Draft a one-page rules-of-engagement document for a lab target.
  2. Exploration and mapping

    Learn the application: features, roles, state changes, API surface.

    1–2 weeks

    Learn

    • Manual crawl before any automation
    • Site map and parameter inventory

    Do

    • Produce a parameter inventory for one authenticated flow.
    • Note every place the app changes server state.
  3. Authentication and session handling

    Login, token lifetime, password reset, MFA order — where logic flaws concentrate.

    1 week

    Learn

    • Token formats and expiry
    • Reset flow analysis

    Do

    • Map every endpoint reachable without a session and confirm intent with the owner.
  4. Input handling and injection

    Where untrusted data is interpreted as code: SQL, commands, templates, queries.

    1–2 weeks

    Learn

    • Error-based vs blind indications
    • Parameterised queries as the mitigation

    Do

    • Confirm one suspected parameter, then re-test after a fix.
    • Write the exact evidence line a developer needs.
    ToolsSQLMap
  5. Access control

    Object-level and function-level authorisation — the class automation cannot see.

    1–2 weeks

    Learn

    • Two-account matrix method
    • Indirect reference patterns

    Do

    • Build a role/endpoint matrix for a lab app with two users.
  6. Client-side and browser behaviour

    DOM sinks, CORS, cookie flags, caching and the origin model.

    1 week

    Learn

    • Where browser policy is and is not enforced
    • PostMessage and third-party script risk

    Do

    • Explain one CORS response to a developer without using the word 'vulnerable'.
    Toolsffuf
  7. Verification and false positives

    Reproduce from a clean session, then prove the negative case too.

    1 week

    Learn

    • Manual confirmation of scanner output
    • Timing, caching and flakiness

    Do

    • Take five scanner findings and mark three as not reportable, with reasons.
    ToolsNuclei
  8. Reporting and retest

    Impact language, reproduction steps, remediation that fits the codebase.

    1 week

    Learn

    • Structure: condition, evidence, impact, fix
    • Severity rationale over severity labels

    Do

    • Write one finding two ways: for a developer and for a manager.

Tools in this path

Each tool page carries installation steps, commands and the errors you will hit.