../web

// web · 01 / 08

Scope & recon

Map before you poke

Practice this only on a lab you own, or a program whose scope you have read.

  • Scope — allowed hosts/paths
  • Recon — headers · forms · roles
  • Hypothesis — one bug class
  • Proof — request → impact

// terminal

Recon box. Fingerprint lab.app
lab@shell:~$
  • Headers (curl -I http://lab.app)
  • Stack guess (tech)

// check yourself

First step on a new in-scope site?

Web attacks — Prashant Dangi