├── Web Penetration Testing Roadmap
│
│ ├── Foundations
│ │ ├── Networking Basics (TCP/IP, DNS, HTTP)
│ │ ├── Web Technologies (HTML, CSS, JavaScript)
│ │ ├── Operating Systems (Linux, Windows)
│ │ └── Programming & Scripting (Python, Bash, PHP)
│
│ ├── Security Fundamentals
│ │ ├── Cryptography & Hashing
│ │ ├── Authentication & Session Management
│ │ └── OWASP Top 10 Overview
│
│ ├── Tools & Environments
│ │ ├── Kali Linux Setup
│ │ ├── Burp Suite, OWASP ZAP
│ │ ├── Nmap, Wireshark, Nikto
│ │ └── Metasploit Framework
│
│ ├── Vulnerability Analysis
│ │ ├── SQL Injection, XSS, CSRF
│ │ ├── File Inclusion, Command Injection
│ │ ├── Authentication Bypass
│ │ └── Business Logic Flaws
│
│ ├── Practice Labs
│ │ ├── DVWA, WebGoat, Juice Shop
│ │ ├── TryHackMe & HackTheBox
│ │ └── Custom Vulnerable Web Apps
│
│ ├── Advanced Topics
│ │ ├── SSRF, XXE, SSTI
│ │ ├── WAF Bypass Techniques
│ │ ├── Exploit Development
│ │ └── Bug Bounty Methodologies
│
│ ├── Reporting & Documentation
│ │ ├── Vulnerability Scoring (CVSS)
│ │ ├── Professional Report Writing
│ │ └── Developer Recommendations
│
│ ├── Certifications
│ │ ├── CompTIA Security+
│ │ ├── CEH (Certified Ethical Hacker)
│ │ ├── OSCP (Offensive Security Certified Professional)
│ │ └── GWAPT (GIAC Web Application Penetration Tester)
│
│ └── Continuous Learning
│ ├── Blogs (PortSwigger, HackerOne, The Hacker News)
│ ├── GitHub Projects & Cheat Sheets
│ └── Security Conferences & Communities
نقشه راه pentenst web 🚨