Operational GraphQL attacking — fingerprinting with graphw00f, dumping the schema via introspection, IDOR on queries, UNION SQLi in arguments, nested-loop DoS and batching brute force, privilege escalation through registerUser mutations, plus GraphQL-Cop and InQL — with a full cheatsheet.
Operational walkthrough of the OWASP API Security Top 10 against a RESTful API — BOLA/IDOR, broken auth brute forcing, mass assignment & excessive data exposure, unrestricted uploads, BFLA, SSRF via file URIs, SQLi, legacy version exposure — driven from Swagger, curl, ffuf and jq, with a full cheatsheet.
Operational SQLMap — targeting GET/POST/request files, tuning level/risk/technique, enumerating databases, cracking hashes, bypassing CSRF/WAF with tamper scripts, and getting a shell with --os-shell — with a full flag cheatsheet.
Operational broken authentication — enumerating users with ffuf, brute forcing passwords / reset tokens / 2FA codes, bypassing rate limits and CAPTCHAs, default creds, vulnerable reset logic, auth bypass via direct access and parameter modification, and attacking session tokens — with a full cheatsheet.
An operational walkthrough of HTTP/HTTPS, cURL, headers, methods, status codes and CRUD APIs — the first module of the HTB CWES path — with a full command cheatsheet at the end.
Operational file-upload exploitation — web/reverse shells, bypassing client-side, blacklist, whitelist and content (Content-Type/magic-byte) filters, and abusing limited uploads for XSS/XXE/SSRF/DoS — with a full cheatsheet.
Operational LFI/RFI — path traversal and filter bypasses, source disclosure with php://filter, RCE via data/input/expect wrappers, RFI over HTTP/FTP/SMB, LFI+upload (image/zip/phar), log and session poisoning, and automated fuzzing — with a full cheatsheet.
Operational server-side exploitation — SSRF (port scan, gopher, blind), SSTI (Jinja2/Twig fingerprint and RCE), SSI directives, and XSLT injection — with payloads and a full cheatsheet.
Operational web recon — WHOIS, DNS and dig, subdomain and vhost enumeration, CT logs, fingerprinting, crawling, Google dorks, the Wayback Machine and automation — with a full command cheatsheet.
A field guide to attacking common off-the-shelf apps — WordPress, Joomla, Drupal, Tomcat, Jenkins, Splunk, PRTG, osTicket, GitLab, ColdFusion, CGI/Shellshock, IIS tilde, LDAP, mass assignment and thick clients — discovery, exploitation and a default-credentials table.
Operational brute forcing — attack types, Hydra and Medusa against HTTP basic auth / login forms / SSH / FTP, success-vs-failure conditions, and building targeted wordlists with grep, Username Anarchy and CUPP — with a full cheatsheet.
Operational OS command injection — injection operators, detecting back-end filters, and bypassing blacklists for spaces, characters and commands (tabs, ${IFS}, env-var substring, quotes, case, reverse, base64) plus evasion tools — with a full cheatsheet.
Operational fuzzing with ffuf, gobuster, feroxbuster and wenum — directories, files, recursion, GET/POST parameters, virtual hosts, response filtering, validation and API fuzzing — with a full flag cheatsheet.
The mental map for web pentesting — front end vs back end, architectures, the HTML/CSS/JS trinity, databases and APIs, and the vulnerability classes (OWASP Top 10) each layer exposes. Second module of the HTB CWES path.
Locate client-side JavaScript, recognise and reverse obfuscation (packing, obfuscator.io, JSFuck), beautify and deobfuscate it, analyse what it does, and decode base64/hex/rot13 — with a full cheatsheet.
Operational XSS — the three types, discovery (manual, XSStrike, code review), and exploitation (defacing, phishing, session hijacking / blind XSS), plus prevention — with a full payload and command cheatsheet.
Operational MySQL SQLi — subverting query logic, auth bypass, UNION injection, INFORMATION_SCHEMA enumeration, reading files with LOAD_FILE, writing a web shell with INTO OUTFILE, and mitigation — with a full payload cheatsheet.
Operational web attacks — HTTP verb tampering (auth/filter bypass), IDOR (mass enumeration, encoded references, insecure APIs, chaining to privilege escalation), and XXE (file read, RCE, CDATA, error-based and blind OOB exfiltration) — with a full cheatsheet.