Pentesting Web Checklist V2

Recon phase

  • Large: a whole company with multiple domains

  • Medium: a single domain

  • Small: a single website

chevron-rightLarge scopehashtag
chevron-rightMedium scopehashtag
chevron-rightSmall scopehashtag
chevron-rightNetworkhashtag
chevron-rightPreparationhashtag
chevron-rightInformation Gatheringhashtag

User management

chevron-rightRegistrationhashtag
chevron-rightAuthentication / Login pagehashtag
chevron-rightProfile / Account details / Change password pagehashtag
chevron-rightForgot / Reset passwordhashtag
chevron-rightInput Handlinghashtag
chevron-rightError Handlinghashtag
chevron-rightApplication Logichashtag

Other checks

chevron-rightInfrastructurehashtag
chevron-rightCAPTCHAhashtag
chevron-rightSecurity Headershashtag

Last updated