Web Penetration Testing

Understanding the CSRF Vulnerability (A Beginner’s Guide)

Cross-Site Scripting Exploitation

Comprehensive Guide on Cross-Site Scripting (XSS)

Comprehensive Guide on Unrestricted File Upload

Comprehensive Guide on Open Redirect

Comprehensive Guide to Remote File Inclusion (RFI)

Comprehensive Guide on HTML Injection

Comprehensive Guide on Path Traversal

Comprehensive Guide on Broken Authentication & Session Management

Comprehensive Guide on OS Command Injection

Multiple Ways to Banner Grabbing

Comprehensive Guide on Local File Inclusion (LFI)

Netcat for Pentester

WPScan:WordPress Pentesting Framework

WordPress Pentest Lab Setup in Multiple Ways

Multiple Ways to Crack WordPress login

Drupal: Reverseshell

Joomla: Reverse Shell

WordPress: Reverse Shell

Web Application Pentest Lab Setup on AWS

Web Application Lab Setup on Windows

Web Application Pentest Lab setup Using Docker

Configure Web Application Penetration Testing Lab

Web Shells Penetration Testing

Web Server Lab Setup for Penetration Testing

SMTP Log Poisoning through LFI to Remote Code Execution

Engagement Tools Tutorial in Burp suite

Payload Processing Rule in Burp suite (Part 2)

Payload Processing Rule in Burp suite (Part 1)

Beginners Guide to Burpsuite Payloads (Part 2)

Beginners Guide to Burpsuite Payloads (Part 1)

Burpsuite Encoder & Decoder Tutorial

Multiple Ways To Exploiting HTTP Authentication

Understanding the HTTP Protocol

Multiple Ways to Detect HTTP Options

Multiple Ways to Exploiting PUT Method

Understanding HTTP Authentication Basic and Digest

Web Application Penetration Testing with curl

Beginner Guide to Understand Cookies and Session Management

Understanding Encoding (Beginner’s guide)

Brute Force Website Login Page using Burpsuite (Beginner Guide)

How to Spider Web Applications using Burpsuite

5 Ways to Create Dictionary for Bruteforcing

Shodan a Search Engine for Hackers (Beginner Tutorial)

5 Ways to Directory Bruteforcing on Web Server

Beginner Guide to Google Dorks (Part 1)

Command Injection Exploitation in DVWA using Metasploit (Bypass All Security)

Server Side Injection Exploitation in bWapp

File Upload Exploitation in bWAPP (Bypass All Security)

Hack File upload Vulnerability in DVWA (Bypass All Security)

Apache Log Poisoning through LFI

Web Server Exploitation with LFI and File Upload

RCE with LFI and SSH Log Poisoning

Vulnerability Analysis in Web Application using Burp Scanner

How to set up SQLI Lab in in Kali

Beginner’s Guide to SQL Injection (Part 1)

Beginner Guide to SQL Injection Boolean Based (Part 2)

How to Bypass SQL Injection Filter Manually

Form Based SQL Injection Manually

Dumping Database using Outfile

Manual SQL Injection Exploitation Step by Step

Beginner Guide to Insecure Direct Object References (IDOR)

Comprehensive Guide to Sqlmap (Target Options)

File System Access on Webserver using Sqlmap

Exploiting Form Based Sql Injection using Sqlmap

Exploiting Sql Injection with Nmap and Sqlmap

Easy way to Hack Database using Wizard switch in Sqlmap

SQL Injection Exploitation in Multiple Targets using Sqlmap

Sql Injection Exploitation with Sqlmap and Burp Suite (Burp CO2 Plugin)

Exploiting the Webserver using Sqlmap and Metasploit (OS-Pwn)

Command Injection Exploitation through Sqlmap in DVWA

Shell uploading on Web Server using Sqlmap

Database Penetration Testing using Sqlmap (Part 1)

Command Injection to Meterpreter using Commix

Exploit Command Injection Vulnerability with Commix and Netcat

Powershell Injection Attacks using Commix and Magic Unicorn

Commix-Command Injection Exploiter (Beginner’s Guide)

Penetration Testing in WordPress Website using WordPress Exploit Framework

Vulnerability Analysis in Web Application using Burp Scanner

Fuzzing SQL,XSS and Command Injection using Burp Suite

Shell Uploading in Web Server through PhpMyAdmin

Web Penetration Testing with Tamper Data (Firefox Add-on)

Command Injection Exploitation using Web Delivery (Linux, Windows)

5 Ways to Crawl a Website

29 Comments Web Penetration Testing

  1. Mohit

    hello sir thanks for provide us this awesome site with best tutorials can u please make this list serial vise if it is

  2. Bryan

    Thank you for all the entries in the blog have been very interesting, it would be possible some post-exploitation tutorial on linux web servers, greetings and thanks for sharing your knowledge you are great.

  3. fer

    you are the best, i have no internet conection full time so i had downloaded all your web pages for learning… thank you.. i am from cuba

  4. Charlie

    This is my go to site for CTF strategies, and hints for when I get stuck. I absolutely love your in-depth walkthroughs with pictures and full explanations. As a visual learner I’m so grateful that people like you exist.

    Thank you Sir, keep doing what you do.

  5. Sahil

    Hello Raj,

    Appreciate your sincerity and passion towards sharing wealth and treasure of videos.

    Would you mind sharing one video of SSRF, including SSRF/Blind SSRF.

  6. Naveen

    Your contribution is highly appreciated in the Security domain,

    It would be great if it categorized with vulnerability type means present there are 100 articles on this page but no order is there. it is just my opinion

    Thank you

    1. ramse

      Yes, i will agree with Naveen. If you do some categorization on these blogs like(Begginer, Intermediate and Advanced). It wolud be useful for who are going to start their career in this domain.

  7. Zeeshan Khan


    It will be very much helpful if we can get an attack scenario or exploitation of Clickjacking attack.

    Thank You

  8. GüTersloh Kino

    I’ve bewn exploring for a little for any high-quality articles or weblog posts in this sort of house .
    Exploring in Yahoo I at last stumbled upon this web site.

    Reading this information So i’m happy to express that I have a very juust right uncanny feeling I found
    out just wyat I needed. I mst surely wioll make sure
    to do not forget his web site and provides
    it a look regularly.


Leave a Reply

Your email address will not be published. Required fields are marked *