Week 3

Web enumeration and Burp Suite

Map content and technology stacks, identify web-server weaknesses, and develop a repeatable manual testing workflow in Burp Suite.

Day 15 complete

Content Discovery

Complete THM room Content Discovery

Open daily log
Day 16 complete

Webstacks

Walkthrough of vulnerabilities of MERN, React/Next, Django and LAMP

Open daily log
Day 17 complete

Web Server Attacks

Complete THM rooms Web Server Attacks I, and II

Open daily log
Day 18 complete

Start of Burp Suite

Complete THM room Burpsuite Starter, and Intruder

Open daily log
Day 19 planned

Burp Suite: Repeater and supporting modules

Complete Burp Suite: Repeater and Other Modules, then document a repeatable manual request-testing workflow.

Open daily log
Day 20 planned

Burp Suite: Extensions and workflow practice

Complete Burp Suite: Extensions and repeat the Proxy-to-Repeater workflow on an authorised TryHackMe web lab.

Open daily log
Day 21 planned

SSRF and Recruit

Complete Intro to SSRF, then attempt Recruit independently to connect the first web-vulnerability module.

Open daily log