> For the complete documentation index, see [llms.txt](https://wiki.zacheller.dev/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://wiki.zacheller.dev/web-app-pentest.md).

# Web App Pentest

- [Tools](https://wiki.zacheller.dev/web-app-pentest/tools.md)
- [Burp Suite](https://wiki.zacheller.dev/web-app-pentest/tools/burp-suite.md)
- [THC-Hydra BruteForce](https://wiki.zacheller.dev/web-app-pentest/tools/thc-hydra-bruteforce.md)
- [Injection](https://wiki.zacheller.dev/web-app-pentest/injection.md)
- [SQL Injection](https://wiki.zacheller.dev/web-app-pentest/injection/sql-injection.md)
- [Broken Authentication](https://wiki.zacheller.dev/web-app-pentest/broken-authentication.md)
- [Sensitive Data Exposure](https://wiki.zacheller.dev/web-app-pentest/sensitive-data-exposure.md)
- [SQLite3](https://wiki.zacheller.dev/web-app-pentest/sensitive-data-exposure/sqlite3.md)
- [XML External Entity](https://wiki.zacheller.dev/web-app-pentest/xml-external-entity.md)
- [XML Background](https://wiki.zacheller.dev/web-app-pentest/xml-external-entity/xml-background.md)
- [XPath Injection](https://wiki.zacheller.dev/web-app-pentest/xml-external-entity/xpath-injection.md)
- [Broken Access Control](https://wiki.zacheller.dev/web-app-pentest/broken-access-control.md)
- [Security Misconfiguration](https://wiki.zacheller.dev/web-app-pentest/security-misconfiguration.md)
- [Upload/Download](https://wiki.zacheller.dev/web-app-pentest/upload-download.md)
- [Download Bypass: Poison Null Byte](https://wiki.zacheller.dev/web-app-pentest/upload-download/error-only-.md-and-.pdf-files-are-allowed.md): Error: Only .md and .pdf files are allowed!
- [XSS](https://wiki.zacheller.dev/web-app-pentest/xss.md)
- [DOMXSS](https://wiki.zacheller.dev/web-app-pentest/xss/domxss.md)
- [Persistent XSS](https://wiki.zacheller.dev/web-app-pentest/xss/persistent-xss.md)
- [Reflected (Client-side) XSS](https://wiki.zacheller.dev/web-app-pentest/xss/reflected-client-side-xss.md)
- [Data URLs](https://wiki.zacheller.dev/web-app-pentest/xss/data-urls.md)
- [Insecure Deserialization](https://wiki.zacheller.dev/web-app-pentest/insecure-deserialization.md)
- [Components with Known Vulnerabilities](https://wiki.zacheller.dev/web-app-pentest/components-with-known-vulnerabilities.md)
- [Insufficient Logging and Monitoring](https://wiki.zacheller.dev/web-app-pentest/insufficient-logging-and-monitoring.md)
- [Server-Side Request Forgery (SSRF)](https://wiki.zacheller.dev/web-app-pentest/server-side-request-forgery-ssrf.md)
