Web SecurityWeb Security · Lesson 11
The Tester's Toolkit & Methodology
Proxy interception, scanners, fuzzing and a repeatable process.
Video tutorialTrack course · freeCodeCamp
Speed
Transcript & captions
9/9
| Tool | Use |
|---|---|
| Burp Suite / ZAP | Intercepting proxy, repeater, fuzzing |
| Browser DevTools | Network, storage, DOM and JS inspection |
| nmap | Port and service discovery (in scope) |
| ffuf / dirsearch | Content and parameter discovery |
| sqlmap | Automated injection testing on authorised targets |
| nuclei | Template-driven vulnerability checks |
- 1. Scope and authorise.
- 2. Recon and map every endpoint.
- 3. Test authentication, then authorisation on each role.
- 4. Test input handling: injection, XSS, file upload, deserialisation.
- 5. Test business logic: pricing, quantities, workflow order.
- 6. Verify, capture evidence, rate severity (CVSS) and report.
Automated scanners find the easy 20 percent. Business logic flaws - the expensive ones - are only found by a human who understands the application.
Knowledge check
0/2 answeredAn intercepting proxy lets you...
Business logic flaws are usually found by...