Web Security Study Roadmap
0 of 0 steps completed
Two tiers. Tier 1 is HTB CWES (associate). Tier 2 is HTB CWEE (expert). Each step has a checkbox and a list of resources. Tick steps as you finish them. Progress is saved in this browser.
Tier 1: Associate Level (CWES)
Phase 1: Foundations
Step 1.1 HTTP fundamentals
- BookThe Web Application Hacker's Handbook, Chapter 3 (Web Application Technologies), Stuttard and Pinto
- HTB AcademyWeb Requests
- HTB AcademyIntroduction to Web Applications
- BlogPortSwigger Web Security Academy, HTTP basics
- YouTubeTraversy Media, HTTP Crash Course
Step 1.2 Web proxies and Burp Suite
- HTB AcademyUsing Web Proxies
- BookThe Web Application Hacker's Handbook, Chapter 20 (A Web Application Hacker's Toolkit)
- YouTubeInsiderPhD, Burp Suite for bug bounty
- DocBurp Suite documentation
Step 1.3 Back end languages basics
- BookWeb Security for Developers, Chapter 2, Malcolm McDonald
- DocOWASP Web Security Testing Guide
- YouTubeProgram With Gio, PHP for Beginners
Phase 2: Reconnaissance and Enumeration
Step 2.1 Passive recon
- HTB AcademyInformation Gathering - Web Edition
- BlogProjectDiscovery, recon workflow articles
- BlogSynack blog, reconnaissance
- GitHubawesome-web-hacking
- ToolWHOIS, DNSDumpster, crt.sh, Shodan, Censys, Wayback Machine
Step 2.2 Active recon and fuzzing
- HTB AcademyAttacking Web Applications with Ffuf
- HTB MachineSau, Busqueda, Intentions, MonitorsThree
- GitHubSecLists wordlists
- YouTubeNahamSec, ffuf guide
Step 2.3 Subdomain enumeration
Phase 3: Client Side Attacks
Step 3.1 XSS
- HTB AcademyCross-Site Scripting (XSS)
- PortSwiggerXSS labs, apprentice to expert
- BookThe Web Application Hacker's Handbook, Chapter 12 (Attacking Users: Cross-Site Scripting)
- HackerOneReport 188242, stored XSS
- PayloadsXSS Injection section
- HackTricksXSS page
- YouTubeSTÖK, XSS content
Step 3.2 CSRF and clickjacking
- HTB AcademySession Security
- PortSwiggerCSRF labs, Clickjacking labs
- BookWeb Security for Developers, Chapter 6, Malcolm McDonald
- HackerOneReport 85624, clickjacking
Step 3.3 JavaScript deobfuscation
- HTB AcademyJavaScript Deobfuscation
- GitHubJSFScan, LinkFinder
- BlogAssetnote, finding secrets in JavaScript
Phase 4: Injection Attacks
Step 4.1 SQL injection
- HTB AcademySQL Injection Fundamentals, SQLMap Essentials
- PortSwiggerSQL injection labs, all levels
- BookThe Web Application Hacker's Handbook, Chapter 9 (Attacking Data Stores)
- HackerOneReport 310621, SQL injection
- PayloadsSQL Injection section
- HackTricksSQL Injection page
- YouTubeRana Khalil, SQL injection course
Step 4.2 Command injection
- HTB AcademyCommand Injections
- PortSwiggerOS command injection labs
- PayloadsCommand Injection section
- HackTricksCommand Injection page
- YouTubeIppSec, command injection walkthroughs
Step 4.3 SSTI
- HTB AcademyServer-side Attacks
- PortSwiggerSSTI labs
- PayloadsServer Side Template Injection section
- HackTricksSSTI page
- Tooltplmap
- HackerOneReport 509866, SSTI
Step 4.4 NoSQL injection
- HTB AcademyIntroduction to NoSQL Injection
- PortSwiggerNoSQL injection labs
- PayloadsNoSQL Injection section
Step 4.5 XXE
- HTB AcademyWeb Attacks
- PortSwiggerXXE labs
- PayloadsXXE Injection section
- HackTricksXXE page
Phase 5: Access Control and Authentication
Step 5.1 IDOR and BOLA
- HTB AcademyWeb Attacks, IDOR section
- PortSwiggerAccess control labs
- HackerOneReport 111014, IDOR
- PayloadsInsecure Direct Object References section
Step 5.2 Authentication bypass
- HTB AcademyBroken Authentication
- PortSwiggerAuthentication labs
- BookThe Web Application Hacker's Handbook, Chapter 6 (Attacking Authentication)
- HackerOneHacktivity, authentication bypass reports
Step 5.3 JWT attacks
- HTB AcademySession Security
- PortSwiggerJWT labs
- GitHubjwt_tool
- HackTricksJWT page
- BlogPortSwigger Research, JWT attacks
Step 5.4 Login brute forcing
- HTB AcademyLogin Brute Forcing
- ToolHydra, Medusa
- YouTubeNull Byte, Hydra guide
Phase 6: File Handling and Upload
Step 6.1 File upload attacks
- HTB AcademyFile Upload Attacks
- PortSwiggerFile upload vulnerabilities labs
- PayloadsUpload Insecure Files section
- HackTricksFile Upload page
- HTB MachineEditorial, Celestial, Photobomb
Step 6.2 Path traversal and LFI
- HTB AcademyFile Inclusion
- PortSwiggerPath traversal labs
- PayloadsFile Inclusion section
- HackTricksLFI page
Phase 7: Server Side Attacks
Step 7.1 SSRF
- HTB AcademyServer-side Attacks, SSRF section
- PortSwiggerSSRF labs
- PayloadsServer Side Request Forgery section
- HackTricksSSRF page
- HackerOneReport 1809193, SSRF
Step 7.2 SSI injection
- HTB AcademyServer-side Attacks, SSI section
- PortSwiggerServer side injection topics
- HackTricksSSI Injection page
Phase 8: API and Modern Stack
Step 8.1 REST API testing
- HTB AcademyWeb Service and API Attacks
- PortSwiggerAPI testing labs
- DocOWASP API Security Top 10
- GitHubAPI Security Checklist
Step 8.2 GraphQL
- HTB AcademyAttacking GraphQL
- PortSwiggerGraphQL API labs
- HackTricksGraphQL page
- HackerOneReport 1086878, GraphQL
Phase 9: CMS and Common Applications
Step 9.1 WordPress
- HTB AcademyHacking WordPress
- HTB MachineDevvortex, MonitorsThree
- ToolWPScan
- HackTricksWordPress page
Step 9.2 Laravel
- GitHubPHPGGC
- BlogAmbionics, Laravel exploitation
- DocLaravel documentation, security
- HTB MachineSeventeen, Devvortex
Phase 10: Methodology and Bug Bounty
Step 10.1 Bug bounty process
- HTB AcademyBug Bounty Hunting Process
- BlogBugcrowd, RCE 101
- BlogHackerOne Hacktivity reports
- GitHubHowToHunt methodology
- YouTubeJason Haddix, bug bounty methodology
Phase 11: Reporting
Step 11.1 Report writing
Tier 2: Expert Level (CWEE)
Phase 12: Advanced Foundations
Step 12.1 White box testing
- HTB AcademyIntro to Whitebox Pentesting, Whitebox Attacks
- BookThe Art of Software Security Assessment, Dowd, McDonald, Schuh
- DocOWASP WSTG, review techniques
Step 12.2 Secure code review
- DocOWASP Code Review Guide
- GitHubSemgrep rules
- ToolSemgrep, Checkov
Phase 13: Advanced Injection
Step 13.1 Advanced SQLi
- HTB AcademyAdvanced SQL Injections, Blind SQL Injection
- PortSwiggerSQL injection expert labs
- GitHubsqlmap tamper scripts
- BlogPortSwigger Research, advanced SQLi
Step 13.2 Advanced deserialization
- HTB AcademyIntroduction to Deserialization Attacks, Advanced Deserialization Attacks
- GitHubysoserial, PHPGGC
- PortSwiggerInsecure deserialization labs
- BookAttacking and Exploiting Modern Web Applications, Chapter 6, Onofri and Onofri
Phase 14: Advanced Authentication
Step 14.1 OAuth and SAML
- HTB AcademyOAuth and SAML modules
- PortSwiggerOAuth labs
- HackTricksOAuth page
- BlogPortSwigger Research, OAuth attacks
Phase 15: Advanced Client Side
Step 15.1 Prototype pollution
- HTB AcademyPrototype Pollution
- PortSwiggerPrototype pollution labs
- PayloadsPrototype Pollution section
- HackTricksPrototype Pollution page
Step 15.2 Web cache poisoning
- HTB AcademyWeb Cache Poisoning
- PortSwiggerWeb cache poisoning labs
- BlogJames Kettle, practical web cache poisoning
Phase 16: HTTP and Protocol Attacks
Step 16.1 Request smuggling
- HTB AcademyHTTP Attacks
- PortSwiggerRequest smuggling labs
- BlogJames Kettle, HTTP desync attacks
- GitHubsmuggler
Step 16.2 Host header injection
- HTB AcademyAbusing HTTP Misconfigurations
- PortSwiggerHost header labs
- HackTricksHost Header page
Phase 17: WAF and CDN Bypasses
Step 17.1 WAF bypass techniques
- PayloadsAccount Takeover and WAF bypass notes
- HackTricksWAF bypass page
- ToolWAFW00F
- YouTubeSTÖK, WAF bypass techniques
Step 17.2 CDN origin discovery
- BlogProjectDiscovery, origin discovery
- ToolCloudFlair, Censys
- HackTricksCDN and origin page
Phase 18: GitLab CI/CD Security
Step 18.1 GitLab pipeline security
- DocGitLab CI/CD security documentation
- GitHubgitleaks, trufflehog
- YouTubeGitLab, CI/CD security
Phase 19: Go for Security Tooling
Step 19.1 Go basics
- DocGo documentation
- BookThe Go Programming Language, Donovan and Kernighan
- YouTubefreeCodeCamp, Go full course
Step 19.2 Go security tools
- GitHubnuclei, httpx, subfinder
- BlogProjectDiscovery, building tools in Go
- Toolgovulncheck
Phase 20: Cloud Secure Code Review
Step 20.1 AWS review
Step 20.2 Azure review
Phase 21: Exam Preparation
Step 21.1 CWES exam prep
- DocHTB CWES exam guide
- Blogsecuritypracticetest.com, CWES practice tests
- BlogMotasem Notes, CWES study guide
- Blogfen1x1a CWES review
Step 21.2 CWEE exam prep
- DocHTB CWEE exam guide
- Blogsecuritypracticetest.com, CWEE practice tests
- BlogUndercode Testing, CWEE deep dive
- Blogxenon-2.gitbook.io, CWEE review
- Blogalmounah.github.io, CWEE review