Table of Contents
- Joining the Hunt
- Choosing Your Hunting Ground
- Preparing for an Engagement
- Unsanitized Data; An XSS Case Study
- SQL, Code Injection, and Scanners
- CSRF and Insecure Session Authentication
- Detecting XML External Entities
- Access Control and Security Through Obscurity
- Framework and Application-Specific Vulnerabilities
- Formatting Your Report
- Other Tools
- Other (Out of Scope) Vulnerabilities
- Going Further
- Assessment

