Web — topics

Web — topics

Atomic web-app vulnerability and primitive notes. Pair with the web-application-security learning path for ordering.

Injection

Cross-site / client

Auth / session

Authorisation and logic

Request-layer

File and path

Indirect access

Server-side application

Client-side storage

Subdomain / DNS takeover

Exposed services and misconfigurations

CMS / framework attack surface