$ cat log/2026-10-07-web-cheatsheet.md

Published the Web CheatSheet

I published a browser-readable cheatsheet of the commands and techniques I use most in penetration testing and CTFs.

→ Open the Web CheatSheet

Contents

Each page collects the steps I actually refer to on engagements and in CTFs.

  • Enumeration — the first things to check on a target
  • Web attacks — SQLi, XSS, LFI/RFI, SSTI, OS command injection, XXE and more
  • CMS — common checks for WordPress, Joomla, Grafana and others
  • Shells — getting and stabilising various reverse shells
  • Privilege escalation — local privesc on Linux and Windows

About

This started as personal notes, organised into a single site so I can reach it from anywhere. It is not indexed by search engines (noindex), and I add to it over time.

← Back to the log