Web Testing
Cheatsheet-style reference for web application security testing. This page contains common commands, techniques, and tools used during web application penetration testing.
Port Scanning
nmap -sC -sV -oA scan target.comBasic port scan with version detection and default scripts.
Directory Enumeration
ffuf -w wordlist.txt -u http://target.com/FUZZFast web fuzzer for discovering hidden directories and files.
Subdomain Discovery
subfinder -d target.com -o subdomains.txtPassive subdomain enumeration using multiple data sources.