All cheatsheets
Cheatsheet · intermediate
Web app mapping
Role matrix, proxy workflow, and first-pass attack surface notes before payloads.
Authorized testing only. Practice on systems you own, isolated labs, or targets with written permission. Unauthorized access is illegal.
web
burp
owasp
Proxy setup
Command
# Burp proxy 127.0.0.1:8080 + browser CA installed
Command
# Scope to in-scope hosts only
Command
httpx -u https://target -title -tech-detect -status-code
Map by role
Command
# Pass 1: unauthenticated browse all menus
Command
# Pass 2: standard user — every form, upload, export
Command
# Pass 3: privileged role — admin only routes
Command
# Diff histories: direct-object access candidates
Content & params
Command
ffuf -u https://target/FUZZ -w /usr/share/seclists/Discovery/Web-Content/common.txt -mc all -fc 404
Command
katana -u https://target -d 3 -o urls.txt
Command
arjun -u https://target/api/item --get
Finding seed template
Command
Title: Severity: Endpoint/Param: Auth context: Impact: Repro steps: Evidence: Remediation:
Checklist
- Role/object matrix started
- High-value functions listed (auth, upload, admin, pay)
- IDs and tokens noted for IDOR tests
- No payload thrash before map exists