Skip to content
OWASP Web Security Testing Guide v4.2

The Trove library · other

OWASP Web Security Testing Guide v4.2

By OWASP Foundation

The OWASP Web Security Testing Guide (WSTG) is a comprehensive guide to testing the security of web applications. It provides a framework of best practices used by penetration testers and security professionals worldwide, with 100+ individual test procedures covering information gathering, authentication, authorization, session management, input validation, cryptography, business logic, client-side, and API testing.

  • 155 pages
  • 155 chapters
  • Updated February 19, 2026

Free to add

Read a preview
Use with your AI agent

Add the book to your library, then connect Trove to the AI tool you use.

See installation options

A look inside · First page

OWASP Web Security Testing Guide v4.2

The OWASP Web Security Testing Guide (WSTG) is a comprehensive guide to testing the security of web applications and web services. Created by the collaborative efforts of cybersecurity professionals and dedicated volunteers, the WSTG provides a framework of best practices used by penetration testers and organizations all over the world.

This book contains the complete WSTG, organized by testing category. Each individual test procedure is identified by its WSTG-XXXX-NN code for easy reference.

About This Edition

Testing Categories

CodeCategoryTests
INFOInformation Gathering10
CONFConfiguration & Deployment Management14
IDNTIdentity Management5
ATHNAuthentication11
ATHZAuthorization5 (+2 sub-tests)
SESSSession Management11
INPVInput Validation20 (+9 sub-tests)
ERRHError Handling2
CRYPWeak Cryptography4
BUSLBusiness Logic11
CLNTClient-side15 (+1 sub-test)
APITAPI Testing4

Add this book to your library to keep reading.

What’s inside

07Web Application Security Testingp. 7

09Information Gatheringp. 9

18WSTG-INFO-09: Fingerprint Web Applicationp. 18

20Configuration and Deployment Management Testingp. 20

28WSTG-CONF-08: Test RIA Cross Domain Policyp. 28

35Identity Management Testingp. 35

40WSTG-IDNT-05: Testing for Weak or Unenforced Username Policyp. 40
41Authentication Testingp. 41
42WSTG-ATHN-01: Testing for Credentials Transported over an Encrypted Channelp. 42

53Authorization Testingp. 53

61Session Management Testingp. 61

73Input Validation Testingp. 73

76WSTG-INPV-03: Testing for HTTP Verb Tamperingp. 76

95WSTG-INPV-13: Testing for Buffer Overflowp. 95

104Error Handling Testingp. 104

106WSTG-ERRH-02: Testing for Stack Tracesp. 106
107Weak Cryptography Testingp. 107

112Business Logic Testingp. 112

124Client-side Testingp. 124

141API Testingp. 141

146Reportingp. 146

149Appendixp. 149

About this book

The OWASP Web Security Testing Guide (WSTG) is a comprehensive guide to testing the security of web applications. It provides a framework of best practices used by penetration testers and security professionals worldwide, with 100+ individual test procedures covering information gathering, authentication, authorization, session management, input validation, cryptography, business logic, client-side, and API testing.