Web app pentesting methodology
Information gathering (passive reconnaissance)
OSINT
google dorks, recon-ng
...
Reconnaissance/enumeration (active reconnaissance)
Robots.txt
Sitemap.xml
gobuster, wfuzz, ffuf, etc.
...
Initial access
Post exploitation
privilege escalation
...
Persistence
Last updated