OWASP

OWASP Top Ten

OWASP Cheat Sheet Series

https://github.com/tanprathan/OWASP-Testing-Checklist

Juice Shop

OWASP Juice Shop

What expect

3 stages

Burp Suite Fast

Target

Look in the intercepted request architecture

Scan is a pro feature → scanning is nice but not exhaustive

crawling / spidering → go out to different web sites winthin the branch

Active scanning → find issues but not exhaustive

Proxy

intercept request

→ can limit intercept to scope

→ send it to repeater

Extender