Pentesting Web checklist

Recon phase

  • Large: a whole company with multiple domains

  • Medium: a single domain

  • Small: a single website

Large scope

Medium scope

Small scope

Network

Preparation

User management

Registration

Authentication

Session

Profile/Account details

Forgot/reset password

Input handling

Error handling

Application Logic

Other checks

Infrastructure

CAPTCHA

Security Headers

Last updated