Junior Web Pentester
Work the chapters in order โ each assumes the one before it. By the end you can read traffic, find the common web bugs by hand and by reading code, map a target safely, and explain the fix to a developer.
Before you touch anything
Permission and scope come first. Learn what you are allowed to do before learning how.
| 1 | Scope & Rules of Engagement
The difference between a penetration tester and a criminal is permission. Learn what authorisation and scope mean, what a rules-of-engagement document covers, and why it comes first. |
Easy | Free |
HTTP essentials
Read requests and responses fluently and understand why the browser is the attacker's side.
Recommended first: chapter 1
| 2 | How HTTP Works
Read a real request and response, learn the method and status-code vocabulary, and see why the browser is a place attackers control. |
Easy | Free |
| 3 | Where Web Bugs Come From
One idea sits underneath almost every web vulnerability: the application trusted input it should have checked. Learn to see that pattern everywhere. |
Easy | Free |
Injection
Input that becomes code: SQL injection, XSS, command injection and path traversal.
Recommended first: chapter 2
| 4 | SQL Injection
Watch a login form turn an attacker's text into database logic, bypass it with a classic payload, and learn the one fix that actually closes the hole. |
Medium | Free this month |
| 5 | Cross-Site Scripting (XSS)
Get your own JavaScript to run in someone else's browser. Learn the three types, why stealing a cookie is the usual prize, and how output encoding shuts it down. |
Medium | Free this month |
| 6 | Command Injection
When an application builds a shell command out of user input, the input can stop being an argument and start being an instruction. Learn the pattern, the tell-tale sign, and the fix. |
Medium | ๐ Pro |
| 7 | Path Traversal
When a filename comes from the user, "../" can walk out of the folder the app meant and into the rest of the server. Learn how, how to spot it, and the canonical fix. |
Medium | ๐ Pro |
Access, sessions and tokens
Broken access control, password storage, sessions, CSRF and JWTs โ the identity layer.
Recommended first: chapter 2
| 8 | Broken Access Control
The bug you find by changing a number in the URL. Learn IDOR, why it is the most common serious web flaw, and the server-side check that stops it. |
Medium | ๐ Pro |
| 9 | How Passwords Are Stored and Cracked
Why sites store hashes not passwords, how attackers crack a leaked hash, and why a pinch of salt and a slow algorithm change everything. |
Medium | ๐ Pro |
| 10 | Session Management
A login is only as strong as the session it creates. Learn how session cookies work, the three ways they go wrong, and the flags and habits that keep them safe. |
Medium | ๐ Pro |
| 11 | Cross-Site Request Forgery (CSRF)
Your browser attaches your session cookie to every request to a site โ even requests a different site told it to make. Learn how that is abused and the token that stops it. |
Medium | ๐ Pro |
| 12 | JSON Web Tokens (JWT)
A JWT lets a server trust a token instead of looking up a session โ but only if it verifies the signature properly. Learn the structure, the classic mistakes, and how to use them safely. |
Hard | ๐ Pro |
Server-side reach
When a bug escapes the app into the network.
Recommended first: chapter 3
| 13 | Server-Side Request Forgery (SSRF)
When an app fetches a URL you give it, you can point it at things you could never reach yourself โ internal services and cloud metadata. Learn the pattern and the defence. |
Hard | ๐ Pro |
| 14 | XML external entities (XXE) | Coming soon |
Code review
Find the same bugs by reading the source, and write findings people act on.
Recommended first: chapters 3, 4
| 15 | SQL Injection: Code Review
Find the injection by reading the source, not just by poking the app. Learn to trace user input from a source to a dangerous sink and spot the fix. |
Medium | ๐ Pro |
| 16 | Secure Code Review
A repeatable way to read code for security: where to look first, the handful of risky functions to grep for, and how to write a finding a developer can act on. |
Medium | ๐ Pro |
| 17 | XSS: Code Review
Find cross-site scripting by reading templates, not by poking the page. Learn where output encoding is on by default, where it is switched off, and how to spot the unsafe line. |
Medium | ๐ Pro |
| 18 | Access Control: Code Review
Broken access control is a missing check, which makes it the hardest bug to see โ there is nothing on the line, because the line is not there. Learn to review for the check that should exist. |
Medium | ๐ Pro |
Recon
Map a target the quiet way and the loud way โ within scope.
Recommended first: chapter 1
| 19 | Recon & Port Scanning
Before you test anything you map it. Learn passive vs active recon, what a port scan tells you, and how to read nmap output โ on targets you are allowed to test. |
Easy | ๐ Pro |
| 20 | OSINT fundamentals | Coming soon | |
| 21 | Web content discovery | Coming soon |
Putting it together
Chain what you have learned and report it professionally.
Recommended first: chapters 2, 3, 4, 6
| 22 | A guided end-to-end assessment | Coming soon | |
| 23 | Writing the report | Coming soon |