Phase 06 · The Largest Surface

Web & Database Attacks

For most organizations the web application is the front door an attacker actually reaches. This phase brings the tester's toolkit — intercepting proxies, scanners, and deliberate practice targets — to bear on the web and the databases behind it, tying together the web-security and SQL-injection labs you have already worked through.

00

About this phase

Web testing is where automation and manual skill meet. An intercepting proxy like Burp Suite or OWASP ZAP sits between browser and server, letting you read and rewrite every request — the core technique behind exploiting most web flaws. Scanners find the obvious; manual testing in the proxy finds the rest. Practice targets like DVWA provide a legal place to drill file upload, local file inclusion, and remote code execution.

This phase is the offensive frame around the site's deepest existing content: the full Web Application Security suite and the 18-technique SQL Injection track. The new material here is the tooling that drives them in an engagement.
Lessons
6 live
Phase
06 of 08
Status
Complete
01

Lessons & labs in this phase