Pentesting Web Checklist V2

Recon phase

  • Large: a whole company with multiple domains

  • Medium: a single domain

  • Small: a single website

Large scope
Medium scope
Small scope
Network
Preparation
Information Gathering

User management

Registration
Authentication / Login page
Profile / Account details / Change password page
Forgot / Reset password
Input Handling
Error Handling
Application Logic

Other checks

Infrastructure
CAPTCHA
Security Headers

Last updated