Web Application Penetration Testing
From OWASP
OWASP Testing Guide v3 Table of Contents
This is a draft of a section of the new Testing Guide v3. For a stable version, please download the OWASP Testing Guide v2 here.
The following paragraphs describe the Web Application Penetration Testing Methology, split into the 11 subcategories:
4.1 Introduction and Objectives
4.3 Configuration Management Testing
4.7 Session Management Testing

