jinpwn.dev
Posts Archive Cheatsheets About

Type to search posts and cheatsheets.

Type to search posts and cheatsheets.

Posts Archive Cheatsheets About
All cheatsheets Web Pentesting
  • Web MOC
  • Content Discovery
  • Auth & Session
  • SQL Injection
  • NoSQL Injection
  • Command Injection
  • SSTI
  • XSS
  • XXE
  • WEB09 CSRF & CORS
  • Request Smuggling
  • Web Cache Poisoning
  • SSRF
  • File Upload & LFI
  • Deserialization
  • WEB15 Prototype Pollution

Web MOC

Sections Web MOC
  • All cheatsheets
  • Web MOC
  • Content Discovery
  • Auth & Session
  • SQL Injection
  • NoSQL Injection
  • Command Injection
  • SSTI
  • XSS
  • XXE
  • WEB09 CSRF & CORS
  • Request Smuggling
  • Web Cache Poisoning
  • SSRF
  • File Upload & LFI
  • Deserialization
  • WEB15 Prototype Pollution

Web application attack chain. Find hidden surfaces, break auth, inject everything.

Recon #

  • Content Discovery

Auth #

  • Auth & Session

Injection #

  • SQL Injection
  • NoSQL Injection
  • Command Injection
  • SSTI
  • XXE

Client-side #

  • XSS
  • CSRF & CORS

Protocol-level #

  • Request Smuggling
  • Web Cache Poisoning
  • SSRF

Code execution #

  • File Upload & LFI
  • Deserialization
  • Prototype Pollution
Flow

Content discovery first, then test auth. Work injection classes top to bottom. Command injection and SSTI are the fastest paths to shell. File upload and deserialization for RCE when injection doesn’t land.

Next Content Discovery

© 2026 JinPwn