├── Web Hacking Roadmap
│ ├── Web Fundamentals
│ │ ├── HTTP Protocol
│ │ ├── HTML/CSS Basics
│ │ ├── JavaScript Fundamentals
│ │ └── Web Hosting & DNS Concepts
│
│ ├── Reconnaissance
│ │ ├── Passive Recon
│ │ │ ├── Whois, DNS Enumeration
│ │ │ ├── Google Dorking
│ │ │ └── Shodan, Censys
│ │ └── Active Recon
│ │ ├── Nmap, Masscan
│ │ └── Directory Enumeration (Dirb, FFUF)
│
│ ├── Web Technologies
│ │ ├── Backend Languages (PHP, Python, Node.js)
│ │ ├── Databases (MySQL, MongoDB)
│ │ └── Frameworks & CMS (WordPress, Laravel)
│
│ ├── Vulnerability Discovery
│ │ ├── OWASP Top 10
│ │ │ ├── SQL Injection
│ │ │ ├── XSS
│ │ │ ├── CSRF
│ │ │ ├── IDOR
│ │ │ ├── SSRF
│ │ │ ├── RCE
│ │ │ └── Broken Access Control
│
│ ├── Testing Techniques
│ │ ├── Manual Testing Tools (Burp Suite, Postman)
│ │ ├── Input Fuzzing
│ │ └── Request Manipulation
│
│ ├── Authentication & Session Attacks
│ │ ├── Broken Auth Mechanisms
│ │ ├── Session Hijacking
│ │ ├── JWT Manipulation
│ │ └── Cookie Poisoning
│
│ ├── Business Logic Exploits
│ │ ├── Abuse of Application Workflows
│ │ ├── Rate Limit Bypass
│ │ └── Privilege Escalation via Logic Flaws
│
│ ├── Bug Bounty & Platforms
│ │ ├── HackerOne, Bugcrowd
│ │ ├── Responsible Disclosure Best Practices
│ │ └── Report Writing & Writeups
│
│ ├── Exploitation & Challenges
│ │ ├── Remote Code Execution (File Upload, LFI)
│ │ ├── Template Injection
│ │ └── Practice Labs (CTFs, HackTheBox)
│
│ ├── Defense & Mitigation
│ │ ├── Input Validation & Sanitization
│ │ ├── Security Headers
│ │ ├── WAF Configuration
│ │ └── Authentication Best Practices
│
│ └── Labs & Learning Resources
│ ├── DVWA, Juice Shop, PortSwigger Labs
│ ├── TryHackMe, HackTheBox Paths
│ ├── Personal Lab with Docker
│ └── Research & Documentation via Blog
نقشه راه وب هکینگ🚨