Web Hacking - Basic Level
Module 1 - Basics of everything:
A. Basics of web applications
B. Vulnerability scanning
C. DNS and Domain level stuff
D. Intro to burp suite , Setting up & use cases
Module 2 - Recon:
A. What is recon?
B. Using VPS to improve recon
a. Aquatone
b. Nmap
c. Massscan
d. Nessus
C. Low severity issues and how to find them during recon.
a. Subdomain takeover
b. Wordpress vulnerabilities
i. WPscan
ii. CMSscan
D. Chaining low severity bugs to get higher impact.
E. Reporting low severity bugs the correct way.
Module 3 - Finding the “easy money bugs”:
A. Cross Site Scripting:
a. How to find? Where to look? Using Burp suite for finding XSS
b. Interesting case studies of XSS
B. Cross site request forgery
C. Access control & Improper session management issues
D. Insecure subdomains & hidden insecure files
a. Using Wfuzz
b. Using Burp Suite Intruder
Module 4 - How not to suck at bug bounties:
A. You are not paid for bugs, actually you are paid on reports. Better make the
reports good too. Does the good reports have to be very technical?
B. How to avoid duplicate issues?
C. Where can you hunt other than Bugcrowd and Hackerone?