Sponsor of the Day:
Jerkmate
https://portswigger.net/web-security/all-topics
All Web Security Academy topics | Web Security Academy - PortSwigger
An overview of all topics, from beginner to expert level, through the Web Security Academy - brought to you by PortSwigger. Create an account to get started.
web security academytopicsportswigger
https://portswigger.net/web-security/cross-site-scripting/reflected
What is reflected XSS (cross-site scripting)? Tutorial & Examples | Web Security Academy
In this section, we'll explain reflected cross-site scripting, describe the impact of reflected XSS attacks, and spell out how to find reflected XSS ...
xss cross sitetutorial examples websecurity academyreflectedscripting
https://portswigger.net/web-security/access-control
Access control vulnerabilities and privilege escalation | Web Security Academy
In this section, we describe: Privilege escalation. The types of vulnerabilities that can arise with access control. How to prevent access control ...
web security academyaccess controlprivilege escalationvulnerabilities
https://portswigger.net/web-security/cross-site-scripting/dom-based
What is DOM-based XSS (cross-site scripting)? Tutorial & Examples | Web Security Academy
In this section, we'll describe DOM-based cross-site scripting (DOM XSS), explain how to find DOM XSS vulnerabilities, and talk about how to exploit DOM XSS ...
dom based xsscross site scriptingtutorial examples websecurity academy
https://portswigger.net/web-security/file-path-traversal
What is path traversal, and how to prevent it? | Web Security Academy
In this section, we explain: What path traversal is. How to carry out path traversal attacks and circumvent common obstacles. How to prevent path traversal ...
web security academypath traversalprevent
https://portswigger.net/web-security/csrf
What is CSRF (Cross-site request forgery)? Tutorial & Examples | Web Security Academy
In this section, we'll explain what cross-site request forgery is, describe some examples of common CSRF vulnerabilities, and explain how to prevent CSRF ...
cross site requesttutorial examples websecurity academycsrfforgery
https://portswigger.net/web-security/sql-injection
What is SQL Injection? Tutorial & Examples | Web Security Academy
In this section, we explain: What SQL injection (SQLi) is. How to find and exploit different types of SQLi vulnerabilities. How to prevent SQLi. Labs If ...
tutorial examples websql injectionsecurity academy
https://portswigger.net/web-security/xxe
What is XXE (XML external entity) injection? Tutorial & Examples | Web Security Academy
In this section, we'll explain what XML external entity injection is, describe some common examples, explain how to find and exploit various kinds of XXE ...
xml external entitytutorial examples websecurity academyxxeinjection
https://portswigger.net/web-security
Web Security Academy: Free Online Training from PortSwigger
The Web Security Academy is a free online training center for web application security, brought to you by PortSwigger. Create an account to get started.
web security academyfree online trainingportswigger