Web Security — Index

Web Security — Index

BLUF: Learn the architecture and trust boundaries first, then validate one weakness at a time in an owned application with synthetic users and data, preserved telemetry, a minimum proof, a stop condition, cleanup, and a regression test.

Mandatory entry gate

Record the owner, application and API allowlist, user roles, synthetic data, request budget, excluded actions, evidence handling, telemetry sources, proof limit, stop authority, and restoration plan. Use Web Validation Catalog as the exercise contract.

Curriculum order

Stage Entry Exit result
Architecture Web Architecture 101 Diagram includes client, proxy/CDN, application, data stores, identities, secrets, trust boundaries, and logs
Control map Web security control map Weaknesses are separated from ATT&CK, CWE, OWASP, and CVE objects
HTTP and platform foundations 1.2.1 Learn Web/ Learner explains HTTP, DNS, TLS termination, caching, queues, APIs, and application/data tiers
Identity protocols JWT · OAuth · SAML Local verifiers reject wrong issuer, audience, destination, lifetime, replay, algorithm, and key
Bounded validation Attack Web One benign proof per card with telemetry and cleanup
White-box review Java, Node, PHP, database, and dependency notes Source-to-sink evidence and a verified fix
Advanced protocols GraphQL, WebSocket, request parsing, WebAssembly Disposable lab with no shared-user traffic
Web3 draft 1.2.3 Web3/ Testnet/dev-chain only; zero-value identities and hardware or platform key storage

Classification model

Object Use
CWE Software weakness, such as CWE-89 or CWE-918
OWASP Top 10 Versioned awareness and risk category
MITRE ATT&CK Observed adversary behavior and operational objective
CVE Specific vulnerable product/version instance
Validation card Authorized lab procedure, proof, telemetry, mitigation, stop, cleanup, and regression

Restricted material

Evidence minimum

Keep a UTC timeline, request IDs, synthetic identity, exact endpoint, tool/version, request and response samples with secrets removed, application/proxy/database events, alerts, canary result, stop reason, cleanup, and regression-test result.