Skip to content

Conversation

manindar-mohan
Copy link
Contributor

@manindar-mohan manindar-mohan commented Jun 30, 2023

This PR fixes #591.

  • This PR handles the issue and requires no additional PRs.
  • You have validated the need for this change.

What did this PR accomplish?

  • Moved all XSS to chapter 11, client-side testing
  • added sub-sections for XSS

Thank you for your contribution!

@github-actions

This comment was marked as outdated.

@github-actions

This comment was marked as outdated.

@github-actions

This comment was marked as outdated.

@github-actions

This comment was marked as outdated.

@github-actions

This comment was marked as outdated.

@github-actions

This comment was marked as outdated.

Manindar Mohan added 15 commits June 30, 2023 15:44
…Testing/12-Testing_for_Format_String_Injection (OWASP#591)
…Testing/13-Testing_for_Incubated_Vulnerability (OWASP#591)
…Testing/14-Testing_for_HTTP_Splitting_Smuggling (OWASP#591)
…alidation_Testing/16-Testing_for_Host_Header_Injection (OWASP#591)
…lidation_Testing/17-Testing_for_Server-side_Template_Injection (OWASP#591)
…lidation_Testing/18-Testing_for_Server-Side_Request_Forgery (OWASP#591)
@github-actions

This comment was marked as outdated.

Manindar Mohan added 11 commits June 27, 2025 13:26
…n_Testing/08-Testing_for_Weak_Password_Change_or_Reset_Functionalities.md
…n_Testing/09-Testing_for_Weaker_Authentication_in_Alternative_Channel.md
…n_Testing/10-Testing_Multi-Factor_Authentication.md
…ion_Testing/03-Testing_for_SQL_Injection.md
…ion_Testing/03.6-Testing_for_NoSQL_Injection.md
…ion_Testing/05-Testing_for_XML_Injection.md
…ion_Testing/10-Testing_for_Command_Injection.md
…ion_Testing/12-Testing_for_Format_String_Injection.md
…ion_Testing/18-Testing_for_Server-Side_Request_Forgery.md
…esting/01.1-Testing_for_Reflected_Cross_Site_Scripting.md
Copy link

The following links are broken:
FILE:document/4-Web_Application_Security_Testing/04-Authentication_Testing/07-Testing_for_Weak_Security_Question_Answer.md
[✖] 09-Testing_for_Weak_Password_Change_or_Reset_Functionalities.md → Status: 400
[✖] 03-Testing_for_Weak_Lock_Out_Mechanism.md → Status: 400

Copy link

The following mistakes were identified:

/home/runner/work/wstg/wstg/pr/document/4-Web_Application_Security_Testing/07-Input_Validation_Testing/03-Testing_for_SQL_Injection.md
789:104 ✖ Incorrect term: “cheatsheet”, use “cheat sheet” instead terminology
790:61 ✖ Incorrect term: “cheatsheet”, use “cheat sheet” instead terminology
792:71 ✖ Incorrect term: “cheatsheet”, use “cheat sheet” instead terminology

…ion_Testing/03-Testing_for_SQL_Injection.md
Copy link

The following links are broken:
FILE:document/4-Web_Application_Security_Testing/04-Authentication_Testing/07-Testing_for_Weak_Security_Question_Answer.md
[✖] 09-Testing_for_Weak_Password_Change_or_Reset_Functionalities.md → Status: 400
[✖] 03-Testing_for_Weak_Lock_Out_Mechanism.md → Status: 400

Copy link

The following links are broken:
FILE:document/4-Web_Application_Security_Testing/04-Authentication_Testing/08-Testing_for_Weak_Password_Change_or_Reset_Functionalities.md
[✖] ../07-Input_Validation_Testing/17-Testing_for_Host_Header_Injection.md → Status: 400
[✖] 08-Testing_for_Weak_Security_Question_Answer.md → Status: 400

Copy link

The following links are broken:
FILE:document/4-Web_Application_Security_Testing/04-Authentication_Testing/10-Testing_Multi-Factor_Authentication.md
[✖] 09-Testing_for_Weak_Password_Change_or_Reset_Functionalities.md → Status: 400
[✖] 08-Testing_for_Weak_Security_Question_Answer.md → Status: 400
[✖] ../07-Input_Validation_Testing/05-Testing_for_SQL_Injection.md#sql-wildcard-injection → Status: 400
[✖] 03-Testing_for_Weak_Lock_Out_Mechanism.md → Status: 400

Copy link

The following links are broken:
FILE:document/4-Web_Application_Security_Testing/04-Authentication_Testing/10-Testing_Multi-Factor_Authentication.md
[✖] 09-Testing_for_Weak_Password_Change_or_Reset_Functionalities.md → Status: 400

Copy link

The following links are broken:
FILE:document/4-Web_Application_Security_Testing/07-Input_Validation_Testing/03-Testing_for_SQL_Injection.md
[✖] https://wiki.owasp.org/index.php/Automated_Audit_using_SQLMap → Status: 500
[✖] https://www.cgisecurity.com/lib/more_advanced_sql_injection.pdf → Status: 403

Copy link

The following links are broken:
FILE:document/4-Web_Application_Security_Testing/07-Input_Validation_Testing/03-Testing_for_SQL_Injection.md
[✖] https://www.cgisecurity.com/lib/more_advanced_sql_injection.pdf → Status: 403

Copy link

The following links are broken:
FILE:document/4-Web_Application_Security_Testing/07-Input_Validation_Testing/03-Testing_for_SQL_Injection.md
[✖] https://www.cgisecurity.com/lib/more_advanced_sql_injection.pdf → Status: 403

Copy link

github-actions bot commented Jul 1, 2025

The following links are broken:
FILE:document/4-Web_Application_Security_Testing/07-Input_Validation_Testing/03-Testing_for_SQL_Injection.md
[✖] https://www.cgisecurity.com/lib/more_advanced_sql_injection.pdf → Status: 403
[✖] https://blog.checkpoint.com/latest-sql-injection-trends/ → Status: 502

@kingthorin
Copy link
Collaborator

Some of the link checks will be FPs, don't get too worried about it.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
revise Needs quality review, updates, or revision work_in_progress Issue or PR not yet ready for review
Projects
None yet
Development

Successfully merging this pull request may close these issues.

XSS Reorganization
4 participants