Slide Overview
Day 1
Introduction
Web Exploitation
Authentication
Day 2
Information Disclosure
Business Logic Vulnerabilities
Assumptions
Day 3
SQL Injection
💉 Injections 💉
Known Vulnerabilities
Day 4
Cross-site scripting (XSS)
Cross-site Request Forgery (CSRF)
Day 5
Open Redirect & SSRF
Is SSRF a problem?
Day 6
Cryptography
Day 7
# Server-Side Template Injection (SSTI)
Insecure Deserialization
XML External Entities (XXE)