Web application penetration testing is a craft: the same classes of weakness — injection, broken access control, misdesigned proxies — keep reappearing on every engagement. This guide indexes Hmmnm’s hands-on web pentest tutorials in the order we’d teach them, each with lab-ready exploitation detail and concrete mitigations.

Foundations

Injection Classes

Configuration & Trust Boundaries

Infrastructure & Specialty Testing

Every tutorial includes detection steps, exploitation detail, and the fix — use this page as your index.

This article is part of the guided learning path Web Application Pentesting — track your progress there.