~ / methodology / web

Web Application

End-to-end methodology for testing web apps and APIs.

Recon & mapping

  • Enumerate subdomains, endpoints, and technologies
  • Map every input, parameter, and authentication boundary
  • Note roles and where trust decisions are made

Content & endpoint discovery

  • Directory and parameter brute-forcing
  • Mine JavaScript for hidden endpoints and secrets
  • Pull historical URLs for forgotten routes

Vulnerability hunting

  • Access control & IDOR, auth / session / JWT flaws
  • Injection: SQLi, SSTI, command, SSRF
  • Client-side: XSS, CSRF; then business logic

Exploitation & reporting

  • Minimal reproducible PoC
  • Chain low-severity bugs into real impact
  • Clear write-up with remediation