Personal learning notes while studying Web Security through PortSwigger Web Security Academy, OWASP, books, and hands-on labs.
| Topic | Status |
|---|---|
| SQL Injection | 🚧 |
| Authentication | ⬜ |
| Path Traversal | ⬜ |
| Command Injection | ⬜ |
| Business Logic | ⬜ |
| Information Disclosure | ⬜ |
| Access Control | ⬜ |
| File Upload | ⬜ |
| Race Conditions | ⬜ |
| SSRF | 🚧 |
| XXE | ⬜ |
| NoSQL Injection | ⬜ |
| API Testing | ⬜ |
| Web Cache Deception | ⬜ |
| Topic | Status |
|---|---|
| XSS | ⬜ |
| CSRF | ⬜ |
| CORS | ⬜ |
| Clickjacking | ⬜ |
| DOM-based Vulnerabilities | ⬜ |
| WebSockets | ⬜ |
| Topic | Status |
|---|---|
| Insecure Deserialization | ⬜ |
| Web LLM Attacks | ⬜ |
| GraphQL | ⬜ |
| SSTI | ⬜ |
| Web Cache Poisoning | ⬜ |
| HTTP Host Header | ⬜ |
| HTTP Request Smuggling | ⬜ |
| OAuth | ⬜ |
| JWT | ⬜ |
| Prototype Pollution | ⬜ |
| Essential Skills | ⬜ |