# Web Application Penetration Testing

## Web

- [Inicio](https://web.mrw0l05zyn.cl/inicio.md)
- [Metodologías y estándares](https://web.mrw0l05zyn.cl/general/metodologias-y-estandares.md)
- [Aplicaciones vulnerables](https://web.mrw0l05zyn.cl/general/aplicaciones-vulnerables.md)
- [Web Application Firewall (WAF)](https://web.mrw0l05zyn.cl/reconocimiento-y-recoleccion-de-informacion/web-application-firewall-waf.md)
- [Subdominios y Virtual Host (VHost)](https://web.mrw0l05zyn.cl/reconocimiento-y-recoleccion-de-informacion/subdominios-y-virtual-host-vhost.md)
- [SSL/TLS y algoritmos de cifrados](https://web.mrw0l05zyn.cl/reconocimiento-y-recoleccion-de-informacion/ssl-tls-y-algoritmos-de-cifrados.md)
- [Certificados](https://web.mrw0l05zyn.cl/reconocimiento-y-recoleccion-de-informacion/certificados.md)
- [Tecnologías web](https://web.mrw0l05zyn.cl/reconocimiento-y-recoleccion-de-informacion/tecnologias-web.md)
- [HTTP security headers](https://web.mrw0l05zyn.cl/escaneo-y-enumeracion/http-security-headers.md)
- [HTTP methods (verbs)](https://web.mrw0l05zyn.cl/escaneo-y-enumeracion/http-methods-verbs.md)
- [Crawling y spidering](https://web.mrw0l05zyn.cl/escaneo-y-enumeracion/crawling-y-spidering.md)
- [Fuzzing](https://web.mrw0l05zyn.cl/escaneo-y-enumeracion/fuzzing.md)
- [Directorios](https://web.mrw0l05zyn.cl/escaneo-y-enumeracion/fuzzing/directorios.md)
- [Archivos](https://web.mrw0l05zyn.cl/escaneo-y-enumeracion/fuzzing/archivos.md)
- [Extensiones](https://web.mrw0l05zyn.cl/escaneo-y-enumeracion/fuzzing/extensiones.md)
- [Parámetros](https://web.mrw0l05zyn.cl/escaneo-y-enumeracion/fuzzing/parametros.md)
- [GET](https://web.mrw0l05zyn.cl/escaneo-y-enumeracion/fuzzing/parametros/get.md)
- [POST](https://web.mrw0l05zyn.cl/escaneo-y-enumeracion/fuzzing/parametros/post.md)
- [Wordlists](https://web.mrw0l05zyn.cl/escaneo-y-enumeracion/fuzzing/wordlists.md)
- [Compresión y ofuscación](https://web.mrw0l05zyn.cl/escaneo-y-enumeracion/compresion-y-ofuscacion.md)
- [Herramientas automatizadas](https://web.mrw0l05zyn.cl/escaneo-y-enumeracion/herramientas-automatizadas.md)
- [API keys](https://web.mrw0l05zyn.cl/explotacion/api-keys.md)
- [Clickjacking](https://web.mrw0l05zyn.cl/explotacion/clickjacking.md)
- [HTTP methods (verbs)](https://web.mrw0l05zyn.cl/explotacion/http-methods-verbs.md)
- [Input data validation](https://web.mrw0l05zyn.cl/explotacion/input-data-validation.md)
- [HTTP Host header](https://web.mrw0l05zyn.cl/explotacion/http-host-header.md)
- [Autenticación y autorización](https://web.mrw0l05zyn.cl/explotacion/autenticacion-y-autorizacion.md)
- [Cookie](https://web.mrw0l05zyn.cl/explotacion/autenticacion-y-autorizacion/cookie.md)
- [JSON Web Token (JWT)](https://web.mrw0l05zyn.cl/explotacion/autenticacion-y-autorizacion/json-web-token-jwt.md)
- [OAuth](https://web.mrw0l05zyn.cl/explotacion/autenticacion-y-autorizacion/oauth.md)
- [SAML](https://web.mrw0l05zyn.cl/explotacion/autenticacion-y-autorizacion/saml.md)
- [Same-origin policy (SOP)](https://web.mrw0l05zyn.cl/explotacion/same-origin-policy-sop.md)
- [Cross-origin resource sharing (CORS)](https://web.mrw0l05zyn.cl/explotacion/same-origin-policy-sop/cross-origin-resource-sharing-cors.md)
- [Cross-site scripting (XSS)](https://web.mrw0l05zyn.cl/explotacion/cross-site-scripting-xss.md)
- [Cross-site request forgery (CSRF)](https://web.mrw0l05zyn.cl/explotacion/cross-site-request-forgery-csrf.md)
- [File upload](https://web.mrw0l05zyn.cl/explotacion/file-upload.md)
- [Path traversal & file inclusion](https://web.mrw0l05zyn.cl/explotacion/path-traversal-and-file-inclusion.md)
- [Command injection](https://web.mrw0l05zyn.cl/explotacion/command-injection.md)
- [Node.js](https://web.mrw0l05zyn.cl/explotacion/command-injection/node.js.md)
- [SQL injection (SQLi)](https://web.mrw0l05zyn.cl/explotacion/sql-injection-sqli.md)
- [MySQL / MariaDB](https://web.mrw0l05zyn.cl/explotacion/sql-injection-sqli/mysql-mariadb.md)
- [Microsoft SQL Server](https://web.mrw0l05zyn.cl/explotacion/sql-injection-sqli/microsoft-sql-server.md)
- [PostgreSQL](https://web.mrw0l05zyn.cl/explotacion/sql-injection-sqli/postgresql.md)
- [Oracle](https://web.mrw0l05zyn.cl/explotacion/sql-injection-sqli/oracle.md)
- [sqlmap](https://web.mrw0l05zyn.cl/explotacion/sql-injection-sqli/sqlmap.md)
- [NoSQL injection (NoSQLi)](https://web.mrw0l05zyn.cl/explotacion/nosql-injection-nosqli.md)
- [XML external entity (XXE) injection](https://web.mrw0l05zyn.cl/explotacion/xml-external-entity-xxe-injection.md)
- [CRLF injection](https://web.mrw0l05zyn.cl/explotacion/crlf-injection.md)
- [XPath injection](https://web.mrw0l05zyn.cl/explotacion/xpath-injection.md): XML Path Language (XPath) injection
- [LDAP injection](https://web.mrw0l05zyn.cl/explotacion/ldap-injection.md)
- [PDF injection](https://web.mrw0l05zyn.cl/explotacion/pdf-injection.md)
- [Server-side template injection (SSTI)](https://web.mrw0l05zyn.cl/explotacion/server-side-template-injection-ssti.md)
- [Server-side include (SSI) injection](https://web.mrw0l05zyn.cl/explotacion/server-side-include-ssi-injection.md)
- [Server-side parameter pollution](https://web.mrw0l05zyn.cl/explotacion/server-side-parameter-pollution.md)
- [Server-side request forgery (SSRF)](https://web.mrw0l05zyn.cl/explotacion/server-side-request-forgery-ssrf.md)
- [Web cache poisoning](https://web.mrw0l05zyn.cl/explotacion/web-cache-poisoning.md)
- [HTTP request smuggling](https://web.mrw0l05zyn.cl/explotacion/http-request-smuggling.md)
- [Prototype pollution](https://web.mrw0l05zyn.cl/explotacion/prototype-pollution.md)
- [Type juggling](https://web.mrw0l05zyn.cl/explotacion/type-juggling.md)
- [GraphQL](https://web.mrw0l05zyn.cl/explotacion/graphql.md)
- [Open redirect](https://web.mrw0l05zyn.cl/explotacion/open-redirect.md)
- [Content Management System (CMS)](https://web.mrw0l05zyn.cl/explotacion/content-management-system-cms.md)
- [WordPress](https://web.mrw0l05zyn.cl/explotacion/content-management-system-cms/wordpress.md)
- [Websocket](https://web.mrw0l05zyn.cl/explotacion/websocket.md)
- [Deserialization](https://web.mrw0l05zyn.cl/explotacion/deserialization.md)
- [Flash](https://web.mrw0l05zyn.cl/explotacion/flash.md)
- [C#](https://web.mrw0l05zyn.cl/revision-de-codigo/c.md)
- [Java](https://web.mrw0l05zyn.cl/revision-de-codigo/java.md)
- [JavaScript](https://web.mrw0l05zyn.cl/revision-de-codigo/javascript.md)
- [Web application penetration testing](https://web.mrw0l05zyn.cl/checklist/web-application-penetration-testing.md)
- [Web API penetration testing](https://web.mrw0l05zyn.cl/checklist/web-api-penetration-testing.md)
