iwlusytd.wikiPENTEST JOURNAL / EN
EXPLORING THE ATTACK SURFACEVOL. 01 / SEPTEMBER 2026

Beyond the
interface_

Pentesting. Web vulnerabilities.
The logic you cannot see
in the browser.

14 articles
from fundamentals to manual testing
UNDERSTAND → TEST → REMEDIATEExplore the journal ↓
DEEP DIVE / ACCESS CONTROL
ACCOUNT AGET /api/orders/B-104
EXPECTED403 Forbidden
IN FOCUS

IDOR: another user’s object.
One familiar request.

Two accounts. One changed identifier.
Where authentication ends and authorization begins.

WEB SECURITY · 3 MINRead the analysis ↗

Technical journal/ 14

PRACTICE WITH THE WHY EXPLAINED

Web security

Trust boundaries in web applications

06
WEB SECURITY / 3 min

IDOR: another user’s object, one familiar request

Why signing in does not grant access to every object. A controlled test with two accounts.

09
WEB SECURITY / 3 min

SQL injection: keep data from becoming code

How the flaw arises, and why an error message is not enough to prove it.

10
WEB SECURITY / 3 min

XSS: understand the context before testing

HTML, an attribute or JavaScript? The same string behaves differently depending on where it appears.

11
WEB SECURITY / 3 min

SSRF: when the server makes the request

URL imports, webhooks and link previews as trust boundaries.

13
WEB SECURITY / 3 min

File uploads: extensions prove nothing

What to check between selecting a file, storing it and serving it back.

API & tools

Requests, sessions and manual testing

07
TOOLS / 3 min

Burp Repeater: one request, one hypothesis

A method for manual HTTP testing without changing a dozen parameters at once.

08
API SECURITY / 3 min

API pentesting goes beyond the contract

Objects, fields, roles and API versions: four dimensions that are easy to overlook.

12
API SECURITY / 3 min

Logging out is a server-side operation

Testing session termination, timeouts and reuse of an old token.

Methodology

From defining scope to verifying fixes

05
METHODOLOGY / 3 min

A pentest starts before the first request

Scope, test roles and stopping criteria. Plan an assessment that produces useful results.

14
METHODOLOGY / 3 min

Turn a finding into a report someone can fix

Evidence, impact and retesting: what should remain after the assessment.

Digital hygiene

Everyday habits that reduce risk

GET IN TOUCH

Something to investigate?

Questions, corrections and ideas for future articles.