A structured walkthrough of PortSwigger Web Security Academy labs — documenting my hands-on offensive security journey, one vulnerability at a time.
This repo is my personal war room. Each lab solution is documented with:
- Approach & Methodology — how I thought about the attack surface
- Exploitation Steps — clear, reproducible steps
| SQL Injection | | XSS | | CSRF | | SSRF | | XXE Injection | | Access Control | | Authentication | | Business Logic | | Clickjacking | | DOM-Based Vulns | | CORS | | Web Cache Poisoning | | Insecure Deserialization | | HTTP Host Header | | OAuth | | JWT | | Prototype Pollution |
- Complete all Apprentice labs
- Complete all Practitioner labs
- Tackle Expert challenges
- Build intuition for real-world bug bounty hunting