Web SecurityWeb Security · Lesson 11

The Tester's Toolkit & Methodology

Proxy interception, scanners, fuzzing and a repeatable process.

Video tutorialTrack course · freeCodeCamp
Speed
Next lesson
Watch 00:00 · 2 checkpoints Watch on YouTube More on this topic
Transcript & captions
9/9
ToolUse
Burp Suite / ZAPIntercepting proxy, repeater, fuzzing
Browser DevToolsNetwork, storage, DOM and JS inspection
nmapPort and service discovery (in scope)
ffuf / dirsearchContent and parameter discovery
sqlmapAutomated injection testing on authorised targets
nucleiTemplate-driven vulnerability checks
  • 1. Scope and authorise.
  • 2. Recon and map every endpoint.
  • 3. Test authentication, then authorisation on each role.
  • 4. Test input handling: injection, XSS, file upload, deserialisation.
  • 5. Test business logic: pricing, quantities, workflow order.
  • 6. Verify, capture evidence, rate severity (CVSS) and report.

Automated scanners find the easy 20 percent. Business logic flaws - the expensive ones - are only found by a human who understands the application.

Knowledge check

0/2 answered

An intercepting proxy lets you...

Business logic flaws are usually found by...