Exploit vulnerability labs at portswigger.net. To understand more, you can click on the following link:
In this session, the following will be included:
-
SQL injection (16/18 labs was completed)
-
Cross-site scripting (13/30 labs was completed)
-
Cross-site request forgery (CSRF)
-
Clickjacking (5/5 labs was completed)
-
Cross-origin resource sharing (CORS) (3/3 labs was completed)
-
XML external entity (XXE) injection
-
Server-side request forgery (SSRF) (5/7 labs was completed)
-
HTTP request smuggling
-
OS command injection (3/5 labs was completed)
-
Path traversal (6/6 labs was completed)
-
Access control vulnerabilities (13/13 labs was completed)
-
Authentication
Labs must using Burp Collaborator's default public server can be not completed.
Each topic includes lab environment, the definition and related labs. All of them are done on Kali Linux's Burp Suite application.
Thanks to Ngu Duy Tinh, a companion who accompanied me to complete the assignments.
For more information, you can read the attached report (Vietnamese version) to gain more perspective about the method, processes of attack, images, and so forth.
My learning progress:

