Web Security — Index
Web Security — Index
BLUF: Learn the architecture and trust boundaries first, then validate one weakness at a time in an owned application with synthetic users and data, preserved telemetry, a minimum proof, a stop condition, cleanup, and a regression test.
Mandatory entry gate
Record the owner, application and API allowlist, user roles, synthetic data, request budget, excluded actions, evidence handling, telemetry sources, proof limit, stop authority, and restoration plan. Use Web Validation Catalog as the exercise contract.
Curriculum order
| Stage | Entry | Exit result |
|---|---|---|
| Architecture | Web Architecture 101 | Diagram includes client, proxy/CDN, application, data stores, identities, secrets, trust boundaries, and logs |
| Control map | Web security control map | Weaknesses are separated from ATT&CK, CWE, OWASP, and CVE objects |
| HTTP and platform foundations | 1.2.1 Learn Web/ | Learner explains HTTP, DNS, TLS termination, caching, queues, APIs, and application/data tiers |
| Identity protocols | JWT · OAuth · SAML | Local verifiers reject wrong issuer, audience, destination, lifetime, replay, algorithm, and key |
| Bounded validation | Attack Web | One benign proof per card with telemetry and cleanup |
| White-box review | Java, Node, PHP, database, and dependency notes | Source-to-sink evidence and a verified fix |
| Advanced protocols | GraphQL, WebSocket, request parsing, WebAssembly | Disposable lab with no shared-user traffic |
| Web3 draft | 1.2.3 Web3/ | Testnet/dev-chain only; zero-value identities and hardware or platform key storage |
Classification model
| Object | Use |
|---|---|
| CWE | Software weakness, such as CWE-89 or CWE-918 |
| OWASP Top 10 | Versioned awareness and risk category |
| MITRE ATT&CK | Observed adversary behavior and operational objective |
| CVE | Specific vulnerable product/version instance |
| Validation card | Authorized lab procedure, proof, telemetry, mitigation, stop, cleanup, and regression |
Restricted material
- SQLMap and HTTP request-smuggling pages are withheld from publication until their destructive, shared-traffic, evasion, and post-exploitation sections are converted.
- Payload collections and raw tool transcripts are reference material, not curriculum entry points.
- Web3 material remains draft until key storage and sign-in semantics are validated.
Evidence minimum
Keep a UTC timeline, request IDs, synthetic identity, exact endpoint, tool/version, request and response samples with secrets removed, application/proxy/database events, alerts, canary result, stop reason, cleanup, and regression-test result.