A look inside · First page
OWASP Web Security Testing Guide v4.2
The OWASP Web Security Testing Guide (WSTG) is a comprehensive guide to testing the security of web applications and web services. Created by the collaborative efforts of cybersecurity professionals and dedicated volunteers, the WSTG provides a framework of best practices used by penetration testers and organizations all over the world.
This book contains the complete WSTG, organized by testing category. Each individual test procedure is identified by its WSTG-XXXX-NN code for easy reference.
About This Edition
Testing Categories
Code Category Tests INFO Information Gathering 10 CONF Configuration & Deployment Management 14 IDNT Identity Management 5 ATHN Authentication 11 ATHZ Authorization 5 (+2 sub-tests) SESS Session Management 11 INPV Input Validation 20 (+9 sub-tests) ERRH Error Handling 2 CRYP Weak Cryptography 4 BUSL Business Logic 11 CLNT Client-side 15 (+1 sub-test) APIT API Testing 4
Add this book to your library to keep reading.
What’s inside 01 OWASP Web Security Testing Guide v4.2 p. 1
05 The Web Security Testing Framework p. 5
06 Penetration Testing Methodologies p. 6
07 Web Application Security Testing p. 7
08 Testing Introduction and Objectives p. 8
09 Information Gathering p. 9
10 WSTG-INFO-01: Conduct Search Engine Discovery Reconnaissance for Information Leakage p. 10
11 WSTG-INFO-02: Fingerprint Web Server p. 11
12 WSTG-INFO-03: Review Webserver Metafiles for Information Leakage p. 12
13 WSTG-INFO-04: Attack Surface Identification p. 13
14 WSTG-INFO-05: Review Web Page Content for Information Leakage p. 14
15 WSTG-INFO-06: Identify Application Entry Points p. 15
16 WSTG-INFO-07: Map Execution Paths Through Application p. 16
17 WSTG-INFO-08: Fingerprint Web Application Framework p. 17
18 WSTG-INFO-09: Fingerprint Web Application p. 18
19 WSTG-INFO-10: Map Application Architecture p. 19
20 Configuration and Deployment Management Testing p. 20
21 WSTG-CONF-01: Test Network Infrastructure Configuration p. 21
22 WSTG-CONF-02: Test Application Platform Configuration p. 22
23 WSTG-CONF-03: Test File Extensions Handling for Sensitive Information p. 23
24 WSTG-CONF-04: Review Old Backup and Unreferenced Files for Sensitive Information p. 24
25 WSTG-CONF-05: Enumerate Infrastructure and Application Admin Interfaces p. 25
26 WSTG-CONF-06: Test HTTP Methods p. 26
27 WSTG-CONF-07: Test HTTP Strict Transport Security p. 27
28 WSTG-CONF-08: Test RIA Cross Domain Policy p. 28
29 WSTG-CONF-09: Test File Permission p. 29
30 WSTG-CONF-10: Test for Subdomain Takeover p. 30
31 WSTG-CONF-11: Test Cloud Storage p. 31
32 WSTG-CONF-12: Testing for Content Security Policy p. 32
33 WSTG-CONF-13: Test Path Confusion p. 33
34 WSTG-CONF-14: Test Other HTTP Security Header Misconfigurations p. 34
35 Identity Management Testing p. 35
36 WSTG-IDNT-01: Test Role Definitions p. 36
37 WSTG-IDNT-02: Test User Registration Process p. 37
38 WSTG-IDNT-03: Test Account Provisioning Process p. 38
39 WSTG-IDNT-04: Testing for Account Enumeration and Guessable User Account p. 39
40 WSTG-IDNT-05: Testing for Weak or Unenforced Username Policy p. 40
41 Authentication Testing p. 41
42 WSTG-ATHN-01: Testing for Credentials Transported over an Encrypted Channel p. 42
43 WSTG-ATHN-02: Testing for Default Credentials p. 43
44 WSTG-ATHN-03: Testing for Weak Lock Out Mechanism p. 44
45 WSTG-ATHN-04: Testing for Bypassing Authentication Schema p. 45
46 WSTG-ATHN-05: Testing for Vulnerable Remember Password p. 46
47 WSTG-ATHN-06: Testing for Browser Cache Weaknesses p. 47
48 WSTG-ATHN-07: Testing for Weak Authentication Methods p. 48
49 WSTG-ATHN-08: Testing for Weak Security Question Answer p. 49
50 WSTG-ATHN-09: Testing for Weak Password Change or Reset Functionalities p. 50
51 WSTG-ATHN-10: Testing for Weaker Authentication in Alternative Channel p. 51
52 WSTG-ATHN-11: Testing Multi-Factor Authentication (MFA) p. 52
53 Authorization Testing p. 53
54 WSTG-ATHZ-01: Testing Directory Traversal File Include p. 54
55 WSTG-ATHZ-02: Testing for Bypassing Authorization Schema p. 55
56 WSTG-ATHZ-03: Testing for Privilege Escalation p. 56
57 WSTG-ATHZ-04: Testing for Insecure Direct Object References p. 57
58 WSTG-ATHZ-05: Testing for OAuth Weaknesses p. 58
59 WSTG-ATHZ-05.1: Testing for OAuth Authorization Server Weaknesses p. 59
60 WSTG-ATHZ-05.2: Testing for OAuth Client Weaknesses p. 60
61 Session Management Testing p. 61
62 WSTG-SESS-01: Testing for Session Management Schema p. 62
63 WSTG-SESS-02: Testing for Cookies Attributes p. 63
64 WSTG-SESS-03: Testing for Session Fixation p. 64
65 WSTG-SESS-04: Testing for Exposed Session Variables p. 65
66 WSTG-SESS-05: Testing for Cross Site Request Forgery p. 66
67 WSTG-SESS-06: Testing for Logout Functionality p. 67
68 WSTG-SESS-07: Testing Session Timeout p. 68
69 WSTG-SESS-08: Testing for Session Puzzling p. 69
70 WSTG-SESS-09: Testing for Session Hijacking p. 70
71 WSTG-SESS-10: Testing JSON Web Tokens p. 71
72 WSTG-SESS-11: Testing for Concurrent Sessions p. 72
73 Input Validation Testing p. 73
74 WSTG-INPV-01: Testing for Reflected Cross Site Scripting p. 74
75 WSTG-INPV-02: Testing for Stored Cross Site Scripting p. 75
76 WSTG-INPV-03: Testing for HTTP Verb Tampering p. 76
77 WSTG-INPV-04: Testing for HTTP Parameter Pollution p. 77
78 WSTG-INPV-05: Testing for SQL Injection p. 78
79 WSTG-INPV-05.1: Testing for Oracle p. 79
80 WSTG-INPV-05.2: Testing for MySQL p. 80
81 WSTG-INPV-05.3: Testing for SQL Server p. 81
82 WSTG-INPV-05.4: Testing PostgreSQL p. 82
83 WSTG-INPV-05.5: Testing for MS Access p. 83
84 WSTG-INPV-05.6: Testing for NoSQL Injection p. 84
85 WSTG-INPV-05.7: Testing for ORM Injection p. 85
86 WSTG-INPV-05.8: Testing for Client-side p. 86
87 WSTG-INPV-06: Testing for LDAP Injection p. 87
88 WSTG-INPV-07: Testing for XML Injection p. 88
89 WSTG-INPV-08: Testing for SSI Injection p. 89
90 WSTG-INPV-09: Testing for XPath Injection p. 90
91 WSTG-INPV-10: Testing for IMAP SMTP Injection p. 91
92 WSTG-INPV-11: Testing for Code Injection p. 92
93 WSTG-INPV-11.1: Testing for File Inclusion p. 93
94 WSTG-INPV-12: Testing for Command Injection p. 94
95 WSTG-INPV-13: Testing for Buffer Overflow p. 95
96 WSTG-INPV-13b: Testing for Format String Injection p. 96
97 WSTG-INPV-14: Testing for Incubated Vulnerability p. 97
98 WSTG-INPV-15: Testing for HTTP Response Splitting p. 98
99 WSTG-INPV-16: Testing for HTTP Request Smuggling p. 99
100 WSTG-INPV-17: Testing for Host Header Injection p. 100
101 WSTG-INPV-18: Testing for Server-side Template Injection p. 101
102 WSTG-INPV-19: Testing for Server-Side Request Forgery p. 102
103 WSTG-INPV-20: Testing for Mass Assignment p. 103
104 Error Handling Testing p. 104
105 WSTG-ERRH-01: Testing for Improper Error Handling p. 105
106 WSTG-ERRH-02: Testing for Stack Traces p. 106
107 Weak Cryptography Testing p. 107
108 WSTG-CRYP-01: Testing for Weak Transport Layer Security p. 108
109 WSTG-CRYP-02: Testing for Padding Oracle p. 109
110 WSTG-CRYP-03: Testing for Sensitive Information Sent via Unencrypted Channels p. 110
111 WSTG-CRYP-04: Testing for Weak Encryption p. 111
112 Business Logic Testing p. 112
113 WSTG-BUSL-00: Introduction to Business Logic p. 113
114 WSTG-BUSL-01: Test Business Logic Data Validation p. 114
115 WSTG-BUSL-02: Test Ability to Forge Requests p. 115
116 WSTG-BUSL-03: Test Integrity Checks p. 116
117 WSTG-BUSL-04: Test for Process Timing p. 117
118 WSTG-BUSL-05: Test Number of Times a Function Can Be Used Limits p. 118
119 WSTG-BUSL-06: Testing for the Circumvention of Work Flows p. 119
120 WSTG-BUSL-07: Test Defenses Against Application Misuse p. 120
121 WSTG-BUSL-08: Test Upload of Unexpected File Types p. 121
122 WSTG-BUSL-09: Test Upload of Malicious Files p. 122
123 WSTG-BUSL-10: Test Payment Functionality p. 123
124 Client-side Testing p. 124
125 WSTG-CLNT-01: Testing for DOM-Based Cross Site Scripting p. 125
126 WSTG-CLNT-01.1: Testing for Self DOM Based Cross-Site Scripting p. 126
127 WSTG-CLNT-02: Testing for JavaScript Execution p. 127
128 WSTG-CLNT-03: Testing for HTML Injection p. 128
129 WSTG-CLNT-04: Testing for Client-side URL Redirect p. 129
130 WSTG-CLNT-05: Testing for CSS Injection p. 130
131 WSTG-CLNT-06: Testing for Client-side Resource Manipulation p. 131
132 WSTG-CLNT-07: Testing Cross Origin Resource Sharing p. 132
133 WSTG-CLNT-08: Testing for Cross Site Flashing p. 133
134 WSTG-CLNT-09: Testing for Clickjacking p. 134
135 WSTG-CLNT-10: Testing WebSockets p. 135
136 WSTG-CLNT-11: Testing Web Messaging p. 136
137 WSTG-CLNT-12: Testing Browser Storage p. 137
138 WSTG-CLNT-13: Testing for Cross Site Script Inclusion p. 138
139 WSTG-CLNT-14: Testing for Reverse Tabnabbing p. 139
140 WSTG-CLNT-15: Testing for Client-side Template Injection p. 140
141 API Testing p. 141
142 WSTG-APIT-00: API Testing Overview p. 142
143 WSTG-APIT-01: API Reconnaissance p. 143
144 WSTG-APIT-02: API Broken Object Level Authorization p. 144
145 WSTG-APIT-99: Testing GraphQL p. 145
146 Reporting p. 146
148 Vulnerability Naming Schemes p. 148
149 Appendix p. 149
150 Testing Tools Resource p. 150
151 Suggested Reading p. 151
153 Encoded Injection p. 153
155 Leveraging Dev Tools p. 155
About this book The OWASP Web Security Testing Guide (WSTG) is a comprehensive guide to testing the security of web applications. It provides a framework of best practices used by penetration testers and security professionals worldwide, with 100+ individual test procedures covering information gathering, authentication, authorization, session management, input validation, cryptography, business logic, client-side, and API testing.
Author OWASP Foundation
Format MARKDOWN
Listed February 19, 2026
Updated February 19, 2026
Subscribers 114
Topics security · audit · best-practices · guide