All cheatsheets

Cheatsheet · intermediate

Web app mapping

Role matrix, proxy workflow, and first-pass attack surface notes before payloads.

Authorized testing only. Practice on systems you own, isolated labs, or targets with written permission. Unauthorized access is illegal.

web
burp
owasp

Proxy setup

Command
# Burp proxy 127.0.0.1:8080 + browser CA installed
Command
# Scope to in-scope hosts only
Command
httpx -u https://target -title -tech-detect -status-code

Map by role

Command
# Pass 1: unauthenticated browse all menus
Command
# Pass 2: standard user — every form, upload, export
Command
# Pass 3: privileged role — admin only routes
Command
# Diff histories: direct-object access candidates

Content & params

Command
ffuf -u https://target/FUZZ -w /usr/share/seclists/Discovery/Web-Content/common.txt -mc all -fc 404
Command
katana -u https://target -d 3 -o urls.txt
Command
arjun -u https://target/api/item --get

Finding seed template

Command
Title:
Severity:
Endpoint/Param:
Auth context:
Impact:
Repro steps:
Evidence:
Remediation:

Checklist

  • Role/object matrix started
  • High-value functions listed (auth, upload, admin, pay)
  • IDs and tokens noted for IDOR tests
  • No payload thrash before map exists