CandleKeep

OWASP Web Security Testing Guide v4.2

by OWASP Foundation

securityauditbest-practicesguide
Pages155
Formatmarkdown
ListedFebruary 19, 2026
UpdatedFebruary 19, 2026
Subscribers59

About

The OWASP Web Security Testing Guide (WSTG) is a comprehensive guide to testing the security of web applications. It provides a framework of best practices used by penetration testers and security professionals worldwide, with 100+ individual test procedures covering information gathering, authentication, authorization, session management, input validation, cryptography, business logic, client-side, and API testing.

155Chapters
1766Topics
155Pages

Preview

OWASP Web Security Testing Guide v4.2

The OWASP Web Security Testing Guide (WSTG) is a comprehensive guide to testing the security of web applications and web services. Created by the collaborative efforts of cybersecurity professionals and dedicated volunteers, the WSTG provides a framework of best practices used by penetration testers and organizations all over the world.

This book contains the complete WSTG, organized by testing category. Each individual test procedure is identified by its WSTG-XXXX-NN code for easy reference.

About This Edition

Testing Categories

CodeCategoryTests
INFOInformation Gathering10
CONFConfiguration & Deployment Management14
IDNTIdentity Management5
ATHNAuthentication11
ATHZAuthorization5 (+2 sub-tests)
SESSSession Management11
INPVInput Validation20 (+9 sub-tests)
ERRHError Handling2
CRYPWeak Cryptography4
BUSLBusiness Logic11
CLNTClient-side15 (+1 sub-test)
APITAPI Testing4
Add to library to read more

Table of Contents

Web Application Security Testing

Information Gathering

WSTG-INFO-09: Fingerprint Web Application

Configuration and Deployment Management Testing

WSTG-CONF-08: Test RIA Cross Domain Policy

Identity Management Testing

WSTG-IDNT-05: Testing for Weak or Unenforced Username Policy
Authentication Testing
WSTG-ATHN-01: Testing for Credentials Transported over an Encrypted Channel

Authorization Testing

Session Management Testing

Input Validation Testing

WSTG-INPV-03: Testing for HTTP Verb Tampering

WSTG-INPV-13: Testing for Buffer Overflow

Error Handling Testing

WSTG-ERRH-02: Testing for Stack Traces
Weak Cryptography Testing

Business Logic Testing

Client-side Testing

API Testing

Reporting

Appendix

Add to Library

Free · Live updates included

59 readers subscribed