Web application attack runbooksΒΆ
An application gives up its surface before it gives up anything else, so recon and surface mapping come first and the targeted work follows what they turn up.
- Runbook: Web application surface discovery
- Runbook: Authentication and session testing
- Runbook: JWT attacks
- Runbook: OAuth and SSO attacks
- Runbook: Access control testing
- Runbook: Server-side injection testing
- Runbook: Path traversal
- Runbook: File upload to web shell
- Runbook: Insecure deserialisation
- Runbook: Prototype pollution
- Runbook: Client-side attack testing
- Runbook: HTTP request smuggling and desync
- Runbook: HTTP Host header attacks
- Runbook: Web cache poisoning
- Runbook: Workflow and business logic testing