Once you read this PDF, you will never look at a website the same way again. A simple contact form will look like an open vault. A password reset feature will look like a trap door.
The PDF (clocking in at roughly 800+ pages in its latest version) is the student guide. It assumes you already know what SQL injection and XSS are. It then proceeds to show you how to exploit them in . web-200 offensive security pdf
OffSec recently updated this course to include GraphQL and NoSQL injection, keeping it relevant for the modern API-driven web. Once you read this PDF, you will never