Web

Pentesting Web Applications Mindmap

Version Enumeration

Commits

Out-of-Band (OOB) Exploitation/Exfiltration

Output Redirection

Tools

nikto

dnsrecon

Perform reverse DNS lookup for IPs in subnet 10.10.10.0/24 with a name server at 192.168.1.11:

gobuster

wfuzz

ffuf

aquatone

Default ports:

From Nmap XML:

amass

subfinder

shuffledns

massdns

pdtm

dnsx

chaos

httpx

With an upsteam proxy using proxify:

katana

interactsh

Self-hosted:

nuclei

Sort results:

SSL / TLS:

Using tlsx:

Web scan against a large scope:

Network scan against a large scope:

Last updated