Web — topics

Web — topics

Atomic web-app vulnerability and primitive notes. Pair with the web-application-security learning path for ordering.

Zero-knowledge primer

Tooling primers

Injection

Cross-site / client

Auth / session

Authorisation and logic

Request-layer

File and path

Indirect access

Server-side application

Recon and methodology

Framework CVEs

Modern stack appsec

Modern protocol attack surface

CTF and CVE reference

SSR / hydration audit

Edge runtime appsec

Advanced bug-class deepening

WAF / CDN bypass research

Email authentication / anti-phishing

Client-side storage

Subdomain / DNS takeover

Exposed services and misconfigurations

CMS / framework attack surface