Junior Web Pentester

18 exercises8 chaptersBeginnerHTTP, Injection, Access control, Code review, Recon

Work the chapters in order โ€” each assumes the one before it. By the end you can read traffic, find the common web bugs by hand and by reading code, map a target safely, and explain the fix to a developer.

Chapter 1

Before you touch anything

Permission and scope come first. Learn what you are allowed to do before learning how.

1 Scope & Rules of Engagement
The difference between a penetration tester and a criminal is permission. Learn what authorisation and scope mean, what a rules-of-engagement document covers, and why it comes first.
Course Easy Free
Chapter 2

HTTP essentials

Read requests and responses fluently and understand why the browser is the attacker's side.

Recommended first: chapter 1

2 How HTTP Works
Read a real request and response, learn the method and status-code vocabulary, and see why the browser is a place attackers control.
Course Easy Free
3 Where Web Bugs Come From
One idea sits underneath almost every web vulnerability: the application trusted input it should have checked. Learn to see that pattern everywhere.
Course Easy Free
Chapter 3

Injection

Input that becomes code: SQL injection, XSS, command injection and path traversal.

Recommended first: chapter 2

4 SQL Injection
Watch a login form turn an attacker's text into database logic, bypass it with a classic payload, and learn the one fix that actually closes the hole.
Course Medium Free this month
5 Cross-Site Scripting (XSS)
Get your own JavaScript to run in someone else's browser. Learn the three types, why stealing a cookie is the usual prize, and how output encoding shuts it down.
Course Medium Free this month
6 Command Injection
When an application builds a shell command out of user input, the input can stop being an argument and start being an instruction. Learn the pattern, the tell-tale sign, and the fix.
Course Medium ๐Ÿ”’ Pro
7 Path Traversal
When a filename comes from the user, "../" can walk out of the folder the app meant and into the rest of the server. Learn how, how to spot it, and the canonical fix.
Course Medium ๐Ÿ”’ Pro
Chapter 4

Access, sessions and tokens

Broken access control, password storage, sessions, CSRF and JWTs โ€” the identity layer.

Recommended first: chapter 2

8 Broken Access Control
The bug you find by changing a number in the URL. Learn IDOR, why it is the most common serious web flaw, and the server-side check that stops it.
Course Medium ๐Ÿ”’ Pro
9 How Passwords Are Stored and Cracked
Why sites store hashes not passwords, how attackers crack a leaked hash, and why a pinch of salt and a slow algorithm change everything.
Course Medium ๐Ÿ”’ Pro
10 Session Management
A login is only as strong as the session it creates. Learn how session cookies work, the three ways they go wrong, and the flags and habits that keep them safe.
Course Medium ๐Ÿ”’ Pro
11 Cross-Site Request Forgery (CSRF)
Your browser attaches your session cookie to every request to a site โ€” even requests a different site told it to make. Learn how that is abused and the token that stops it.
Course Medium ๐Ÿ”’ Pro
12 JSON Web Tokens (JWT)
A JWT lets a server trust a token instead of looking up a session โ€” but only if it verifies the signature properly. Learn the structure, the classic mistakes, and how to use them safely.
Course Hard ๐Ÿ”’ Pro
Chapter 5

Server-side reach

When a bug escapes the app into the network.

Recommended first: chapter 3

13 Server-Side Request Forgery (SSRF)
When an app fetches a URL you give it, you can point it at things you could never reach yourself โ€” internal services and cloud metadata. Learn the pattern and the defence.
Course Hard ๐Ÿ”’ Pro
14XML external entities (XXE)Coming soon
Chapter 6

Code review

Find the same bugs by reading the source, and write findings people act on.

Recommended first: chapters 3, 4

15 SQL Injection: Code Review
Find the injection by reading the source, not just by poking the app. Learn to trace user input from a source to a dangerous sink and spot the fix.
Code review Medium ๐Ÿ”’ Pro
16 Secure Code Review
A repeatable way to read code for security: where to look first, the handful of risky functions to grep for, and how to write a finding a developer can act on.
Code review Medium ๐Ÿ”’ Pro
17 XSS: Code Review
Find cross-site scripting by reading templates, not by poking the page. Learn where output encoding is on by default, where it is switched off, and how to spot the unsafe line.
Code review Medium ๐Ÿ”’ Pro
18 Access Control: Code Review
Broken access control is a missing check, which makes it the hardest bug to see โ€” there is nothing on the line, because the line is not there. Learn to review for the check that should exist.
Code review Medium ๐Ÿ”’ Pro
Chapter 7

Recon

Map a target the quiet way and the loud way โ€” within scope.

Recommended first: chapter 1

19 Recon & Port Scanning
Before you test anything you map it. Learn passive vs active recon, what a port scan tells you, and how to read nmap output โ€” on targets you are allowed to test.
Course Easy ๐Ÿ”’ Pro
20OSINT fundamentalsComing soon
21Web content discoveryComing soon
Chapter 8

Putting it together

Chain what you have learned and report it professionally.

Recommended first: chapters 2, 3, 4, 6

22A guided end-to-end assessmentComing soon
23Writing the reportComing soon