Skip to main content

Security Testing Learning Path: Start Here

In short: you learn security testing in 6 milestones on OWASP Juice Shop, an app built to be broken into for practice. You start with the checks any tester can do and end with a full assessment report — always on a legal target on your own machine.

Legal targets only

This path uses Juice Shop (deliberately vulnerable, made for this) and the free PortSwigger Web Security Academy. Never use these techniques on systems you don't own or have written permission to test. See permission and scope.

Before you start​

The pages in this learning path​

PageWhat it's forWhen to open it
This roadmapThe plan and self-checksAt the start of each milestone
Security cheat sheetLearn each idea, with real Juice Shop resultsThe "learn" step
Milestones & Mini-ProjectsTasks, expected results, answer keysThe "test" and "check" steps
Quick ReferenceChecklists, payloads, scanner commands, templatesAny time
Best PracticesSafe, legal, useful habitsAfter Milestone 1, then every engagement
Security testing guideThe service and penetration-test phasesFor the deeper "why"

The milestones​

MilestoneYou learnYou work onRough time
1Scope, headers, errors, baselineRecon + baseline on Juice Shop1 week
2Injection, SQLiLogin bypass + search SQLi1–2 weeks
3Broken access control, authBOLA, JWT, brute force1–2 weeks
4XSS, business logicReflected/stored XSS, price/coupon abuse1–2 weeks
5Scanners in CI (ZAP, SAST, SCA, secrets)An automated pipeline1 week
6CVSS, reporting, a full assessmentA findings report1–2 weeks

Times assume about 5 hours a week.

For each milestone: learn (cheat-sheet sections) → test (the tasks) → check (answer key) → commit your findings and scripts.

Milestone 1: Recon & baseline​

Learn: Permission & scope · What security testing is · Think like an attacker · OWASP Top 10 · Security headers · Reading errors · Baseline checks

Work on: Recon + baseline

Then read: Best Practices, sections 1–2.

Check yourself:

  • What must you have before testing any real system?
  • Which two security headers is Juice Shop missing?
  • Why is a 500 with a SQL error a finding on its own?

Milestone 2: Injection​

Learn: HTTP & auth recap · Injection & SQLi · Quick Reference: Safe test inputs

Work on: Login bypass + search SQLi

Check yourself:

  • Why does ' OR 1=1-- log you in as admin?
  • What is the real fix for SQLi?
  • How do you spot a SQLi point without breaking anything?

Milestone 3: Access control & auth​

Learn: Broken access control · Authentication · Quick Reference: curl recipes, JWT

Work on: BOLA, JWT, brute force

Then read: Best Practices, sections 6–7.

Check yourself:

  • What is BOLA/IDOR, and how do you test for it?
  • What's in a JWT payload, and is it encrypted?
  • Why test with two accounts per role?

Milestone 4: XSS & business logic​

Learn: XSS · Business logic · Common mistakes

Work on: XSS + price/coupon abuse

Check yourself:

  • What's the difference between reflected and stored XSS?
  • Which header reduces XSS impact — and does Juice Shop set it?
  • Why can't a scanner find business-logic flaws?

Milestone 5: Scanners in CI​

Learn: Secrets in code · Vulnerable dependencies · Automated scanning (ZAP) · SAST & dependency scans in CI · Quick Reference: Scanner commands

Work on: An automated pipeline

Then read: Best Practices, sections 3–5.

Check yourself:

  • What's the difference between a ZAP baseline and full scan?
  • Why gate CI on new HIGH/CRITICAL only?
  • Why must a leaked secret be rotated, not just deleted?

Milestone 6: Assessment & report​

Learn: Burp Suite · API & cloud · CVSS & severity · Reporting · Quick Reference: CVSS, Finding template

Work on: A findings report

Then read: Best Practices, sections 8–11.

Check yourself:

  • What makes a finding "Critical"?
  • What goes in the first page of a report?
  • When do you report a critical, and how?

When you get stuck​

ProblemWhat to do
Juice Shop won't startCheck the port (-p 3001:3000); docker logs juice; wait ~30 s for it to boot
A challenge won't solveOpen /#/score-board; Juice Shop has hints and an official companion guide ("Pwning OWASP Juice Shop")
A scanner floods you with findingsFilter to HIGH/CRITICAL; confirm by hand before believing
Not sure if something's a bugAsk: could an attacker gain access, data, or control? If unclear, log it as info

What's next​

  • API-specific security: API testing cheat sheet.
  • Cloud and infrastructure: AWS and Terraform guides.
  • Certifications: PortSwigger BSCP, eJPT, OSCP; ISTQB Security Tester (CT-SEC).

Good resources: OWASP Top 10, WSTG and Cheat Sheet Series; the free PortSwigger Web Security Academy; the book The Web Application Hacker's Handbook.