Skip to content

A curated repository of web application penetration testing notes, labs, and walkthroughs from PortSwigger Academy and real-world exercises. Ideal for anyone learning bug bounty hunting, web app security, and practical pentesting techniques.

License

Notifications You must be signed in to change notification settings

dollarboysushil/web-application-pentesting

Folders and files

NameName
Last commit message
Last commit date

Latest commit

Β 

History

19 Commits
Β 
Β 
Β 
Β 
Β 
Β 
Β 
Β 
Β 
Β 
Β 
Β 
Β 
Β 

Repository files navigation

πŸ’» Web Application Pentesting Repository

GitHub Repo Size GitHub Issues GitHub License GitHub Last Commit

Twitter Follow


πŸš€ About This Repository

This repository contains detailed notes, labs, and walkthroughs from the PortSwigger Web Security Academy and other web application penetration testing resources.

It is designed for anyone interested in:

  • Web Application Penetration Testing
  • Bug Bounty Hunting
  • Burp Suite Certified Practitioner
  • Learning practical security testing methodologies

Note: New topics are continuously being added. Stay tuned for updates!


πŸ—‚οΈ Topics

1. Server-side Attacks

Authentication (13 Labs βœ…)
Business Logic Vulnerabilities (10 Labs βœ…)
Information Disclosure (5 Labs βœ…)
Race Conditions (5 Labs βœ…)
Broken Authentication / Access Control Labs (13 Labs βœ…)
SSRF β€” Server-side Request Forgery (7 Labs βœ…)
SQL injection
Path traversal
Command injection
File upload vulnerabilities
XXE injection
NoSQL injection
API testing
Web cache deception

2. Client-side topics

Cross-Site Request Forgery (CSRF) β€” Client-Side Attacks (12 Labs βœ…)
Cross-Origin Resource Sharing (CORS) β€” Client-Side Attacks (3 Labs βœ…)
Cross-Site Scripting (XSS) (27 Labs Completed)
Clickjacking
DOM-based vulnerabilities
WebSockets

🌐 Connect with Me

Platform Link
Website dollarboysushil.com
Twitter @dollarboysushil
LinkedIn Sushil Poudel
GitHub dollarboysushil
YouTube dollarboysushil

⚑ License

This project is licensed under the MIT License.


Happy Hacking! πŸ”

About

A curated repository of web application penetration testing notes, labs, and walkthroughs from PortSwigger Academy and real-world exercises. Ideal for anyone learning bug bounty hunting, web app security, and practical pentesting techniques.

Topics

Resources

License

Stars

Watchers

Forks

Languages