Pentesting Web checklist
Last updated
Was this helpful?
Last updated
Was this helpful?
(, , , , , )
Permute subdomains ()
Subdomain bruteforce (, )
Identify alive subdomains ()
()
Check for (, , )
Subdomains from subdomains (, , )
Take screenshots (, , )
Get for IP ranges (, , , )
Review latest
Check DMARC/SPF policies ()
Open ports with
Check UDP ports ( or nmap)
Test ()
If got creds, try password for all the services discovered
(also my%00email@mail.com for account tko)
Check for password wordlist ( and )
Test 0auth login functionality for
Test response tampering in authentication
If , check common flaws
Try login with common
Bypass tokens
Create a list of features that are pertaining to a user account only and try
File : , No Size Limit, File extension, Filter Bypass, extension, RCE
Check profile picture URL and find email id/user info or
of all downloadable files (Geolocation, usernames)
HTTP in GET & POST (X Forwarded Host)
Path , LFI and RFI
in any request, change content-type to text/xml
Stored
injection with ' and '--+-
injection
HTTP Request
in previously discovered open ports
Try to discover hidden parameters (or )
Check for test credit card number allowed like 4111 1111 1111 1111 ( )
hosting misconfiguration ()
Test storage
Bypass with OCR tool ()