🎯
Junior Pentester
Build a solid foundation in web application security. Work through the core vulnerability classes every pentester needs to know, from XSS and SQL injection to authentication flaws and SSRF.
62 exercises
4 chapters
← All Tracks
Chapter 1
Cross-Site Scripting
Learn to find and exploit XSS vulnerabilities, from basic reflected and stored XSS to filter bypasses and DOM-based attacks.
Chapter 2
Injection & Execution
Exploit SQL injection, command injection, code execution, LDAP injection, NoSQL injection, server-side template injection, and file inclusion vulnerabilities.
SQL Injection 01
Pro
SQL Injection 02
Pro
SQL Injection 03
Pro
SQL Injection 04
Pro
SQL Injection 05
Pro
SQL Injection 06
Pro
Command Execution 01
Pro
Command Execution 02
Pro
Command Execution 03
Pro
Code Execution 01
Pro
Code Execution 02
Pro
Code Execution 03
Pro
Code Execution 04
Pro
Code Execution 05
Pro
Code Execution 06
Pro
Code Execution 07
Pro
Code Execution 08
Pro
Code Execution 09
Pro
LDAP 01
Pro
LDAP 02
Pro
MongoDB Injection 01
Pro
MongoDB Injection 02
Pro
Server Side Template Injection 01
Pro
Server Side Template Injection 02
Pro
File Include 01
Pro
File Include 02
Pro
Recommended: Complete Chapter 1 first
Chapter 3
Files, Paths & Server-Side Requests
Exploit directory traversal, file upload, XML external entities, open redirects, and server-side request forgery vulnerabilities.
Directory Traversal 01
Pro
Directory Traversal 02
Pro
Directory Traversal 03
Pro
File Upload 01
Pro
File Upload 02
Pro
XML Attacks 01
Pro
XML Attacks 02
Pro
Open Redirect 01
Pro
Open Redirect 02
Pro
Server Side Request Forgery 01
Pro
Server Side Request Forgery 02
Pro
Server Side Request Forgery 03
Pro
Server Side Request Forgery 04
Pro
Recommended: Complete Chapters 1 & 2 first
Chapter 4
Authentication, Authorization & JWT
Identify and exploit authentication bypass, broken access controls, insecure direct object references, and JWT implementation flaws.
Recommended: Complete all previous chapters