0% found this document useful (0 votes)
32 views1 page

Web Hacking 101: A Beginner's Guide

The document outlines a basic web hacking training course consisting of 4 modules. Module 1 covers basics of web applications, vulnerability scanning, and using Burp Suite. Module 2 focuses on reconnaissance, including tools for subdomain enumeration and vulnerability scanning. Module 3 teaches how to find common issues like cross-site scripting and access control bugs. Module 4 discusses improving bug reports for bounty programs and avoiding duplicate issues.

Uploaded by

ma hendra
Copyright
© All Rights Reserved
We take content rights seriously. If you suspect this is your content, claim it here.
Available Formats
Download as PDF, TXT or read online on Scribd
0% found this document useful (0 votes)
32 views1 page

Web Hacking 101: A Beginner's Guide

The document outlines a basic web hacking training course consisting of 4 modules. Module 1 covers basics of web applications, vulnerability scanning, and using Burp Suite. Module 2 focuses on reconnaissance, including tools for subdomain enumeration and vulnerability scanning. Module 3 teaches how to find common issues like cross-site scripting and access control bugs. Module 4 discusses improving bug reports for bounty programs and avoiding duplicate issues.

Uploaded by

ma hendra
Copyright
© All Rights Reserved
We take content rights seriously. If you suspect this is your content, claim it here.
Available Formats
Download as PDF, TXT or read online on Scribd

 

Web Hacking - Basic Level 


Module 1 - Basics of everything:  
A. Basics of web applications 
B. Vulnerability scanning  
C. DNS and Domain level stuff 
D. Intro to burp suite , Setting up & use cases  
 
Module 2 - Recon: 
A. What is recon? 
B. Using VPS to improve recon 
a. Aquatone  
b. Nmap  
c. Massscan  
d. Nessus 
C. Low severity issues and how to find them during recon. 
a. Subdomain takeover  
b. Wordpress vulnerabilities  
i. WPscan  
ii. CMSscan  
D. Chaining low severity bugs to get higher impact.  
E. Reporting low severity bugs the correct way.  
 
Module 3 - Finding the “easy money bugs”: 
A. Cross Site Scripting: 
a. How to find? Where to look? Using Burp suite for finding XSS  
b. Interesting case studies of XSS 
B. Cross site request forgery  
C. Access control & Improper session management issues 
D. Insecure subdomains & hidden insecure files   
a. Using Wfuzz  
b. Using Burp Suite Intruder  
 
 
Module 4 - How not to suck at bug bounties: 
A. You are not paid for bugs, actually you are paid on reports. Better make the 
reports good too. Does the good reports have to be very technical?  
B. How to avoid duplicate issues? 
C. Where can you hunt other than Bugcrowd and Hackerone? 
 

You might also like