Manuals / Security Testing Basics / Chapter 3
A · Common flaws · intermediate · ~35 min · Chapter 3 of 5
Injection & XSS awareness
Know enough XSS/SQLi patterns to recognize them and hand off safely.
Harmless probe
Use a benign marker string. If it renders raw, escalate. Don’t spray real exploits.
Harmless probeDrag stickies · tap for tips
Do this now
Test one form field with a safe marker; note encoding.
Was this step clear?
Chapter learning outcomes
- Reflected vs stored XSS
- Input sinks
- Safe proof-of-concept
Clear these before you leave