top of page

Penetration Testing: Web Application Checklist (WAPT)

5 hours ago
2 min read

Checklists aren't creativity killers. They're seatbelts so you don't forget logout behavior because XSS was shiny.


Use WAPT-style lists as coverage maps, not as 'run every item once and declare victory.'

Penetration Testing: Web Application Checklist (WAPT)

WAPT-style lists help juniors not skip logout testing; they help seniors not forget to revisit scope amendments on day four. Use them as maps, not scorecards.



Authentication and session


Registration, password reset, MFA bypass paths, session fixation, timeout, concurrent sessions, and privilege changes.


Compare cookie flags across apps in the same suite.



Access and business logic


Horizontal and vertical access tests on every object type you mapped. Workflow bypass, price tampering, and rate limits on sensitive actions.


  • Input validation on all verbs, not just POST forms

  • File upload content and storage location

  • CORS, CSP, and security headers as supporting evidence



Infrastructure-facing web


SSRF sinks, template engines, XML parsers, deserialization points, and admin interfaces.


Tailor the checklist to stack and scope—SPA apps need different depth than legacy JSP.


Execute checks only on authorized environments and accounts.


Share checklist coverage gaps with the client in the readout—transparency about what time didn't allow builds credibility.


Small habits compound—what feels like overhead early becomes speed when deadlines hit.


Bring the checklist to readouts—clients like seeing explicit coverage statements.



Adaptive depth


Spend longer on payment and auth than on header trivia unless headers enable real bypasses.


Mark checklist items N/A with reasons—clients prefer honesty over checkbox greenwashing.



Reporting linkage


Map checklist sections to report template headings—saves rewriting at deadline.


Mark deferred items with owner and reason when timeboxed engagements end.


Use checklists to train juniors; don't use them to replace thinking on mature apps.




Worth reading next


Manually Walking a Web Target After Recon


Web Hacking for Pentesters: Cross-Site Scripting (XSS)


Business Logic Flaws and Broken Access Control

Comments


© 2022 by SapiensHack.com (Security)

bottom of page