Hello. Welcome To Secuholic's Webhacking Tutorial.
In the past few years, I've been Pen Testing hundreds of websites, reading numerous books and doing google searches. I could find various technical documents and techniques for beginners, but I could not find systematic documents or tutorials.
So, I decided to write a systematic web hacking tutorial that would help both beginners and professionals.
The tutorial will include:
HTTP Protocol, Proxy, Encoding/Decoding, WEB/WAS/DBMS, etc
GoogleDorking, Banner grabbing, PortScan, Sitemap, Spidering, etc
Injection, Auth and Session, XSS, CSRF, Infomation Exposure, FileUpload/Download, etc
XXE, XSRF, NoSQL, ActiveX, HTML5, Templete Injection, Parser, OOB, Deserialize, etc
Filter Bypass, WAF Bypass, Regex Bypass, etc
webshell, SQLinjeciton, XXE, etc
Bugcrowd, Hackerone, etc
Writeups
Papers
My goal is to post once a week. Starting next week. :)