Skip to content
H1Gdev edited this page Mar 25, 2025 · 46 revisions

Tests

  • Penetration test
    • Black Box
    • Grey Box
    • White Box

Vulnerabilities

  • Information Disclosure
  • Broken Object Level Authorization (BOLA)
  • Broken User Authentication
  • Excessive Data Exposure
  • Lack of Resources and Rate Limiting
  • Broken Function Level Authorization (BFLA)
  • Mass Assignment
  • Security Misconfiguration
  • Injection Flaws
  • Improper Assets Management
  • Business Logic Flaws (BLF)

Security

Bug Bounty

Academy

Testing

  • Kali Linux
  • Burp Suite
    • [Proxy]
    • [Intruder]
      • [Positions]
        • Attack type
          • Sniper
          • Battering ram
          • Pitchfork
          • Cluster bomb
      • [Payloads]
  • Google Chrome
  • Postman
    • HTTP
      • [Params]
      • [Authorization]
      • [Headers]
      • [Body]
      • [Scripts]
        • Pre-request
        • Post-response
      • [Settings]
      • Code snippet
        • Code
    • Collection
    • Environment
      • Variable
        • Type
        • Initial value
        • Current value

Tools

Clone this wiki locally