Pentesting Web checklist
Recon phase
Large: a whole company with multiple domains
Medium: a single domain
Small: a single website
Large scope
Medium scope
Small scope
Network
Preparation
User management
Registration
Authentication
Session
Profile/Account details
Forgot/reset password
Input handling
Error handling
Application Logic
Other checks
Infrastructure
CAPTCHA
Security Headers
Last updated