Web Application Information Gathering

Learn how to perform reconnaissance before testing a web application.

1. Information Gathering

Every web application assessment begins by understanding the application's attack surface. Collect domains, subdomains, historical URLs and exposed technologies before testing.

subfinder -d example.com

httpx

katana

waybackurls

gau

2. Authentication Testing

Authentication is one of the most critical parts of a web application. Verify login functionality, password reset, session management, remember-me functionality, MFA and account lockout mechanisms.

  • Weak Password Policy
  • Broken Authentication
  • Session Fixation
  • Session Hijacking
  • Password Reset Issues

3. Authorization Testing

Verify whether users can access resources belonging to other users by manipulating identifiers or modifying requests.

GET /api/profile/1001

↓

GET /api/profile/1002

Test for:

  • IDOR
  • Privilege Escalation
  • Horizontal Access Control
  • Vertical Access Control

4. API Security

Modern applications rely heavily on REST and GraphQL APIs. Validate authentication, authorization, rate limiting and input validation.

  • JWT Security
  • OAuth Testing
  • Rate Limiting
  • Mass Assignment
  • Broken Object Level Authorization

5. OWASP Top 10

During every assessment, verify whether the application is vulnerable to common OWASP Top 10 issues.

  • Broken Access Control
  • Cryptographic Failures
  • Injection
  • Insecure Design
  • Security Misconfiguration
  • Vulnerable Components
  • Authentication Failures
  • Integrity Failures
  • Logging & Monitoring
  • SSRF

6. Useful Tools

Burp Suite

Nuclei

ffuf

Katana

Subfinder

Amass

httpx

Nmap

OWASP ZAP

7. Conclusion

A successful web application assessment combines manual testing with automation. Never rely solely on scanners. Understanding business logic and application workflows is essential for discovering high-impact vulnerabilities.