Security Testing Learning Path: Start Here
In short: you learn security testing in 6 milestones on OWASP Juice Shop, an app built to be broken into for practice. You start with the checks any tester can do and end with a full assessment report — always on a legal target on your own machine.
This path uses Juice Shop (deliberately vulnerable, made for this) and the free PortSwigger Web Security Academy. Never use these techniques on systems you don't own or have written permission to test. See permission and scope.
Before you start
- Docker, to run Juice Shop:
docker run --rm -d -p 3001:3000 bkimminich/juice-shop. - Comfort with HTTP, JSON and
curl— the API testing cheat sheet, sections 1–9. - A free PortSwigger Web Security Academy account (used from Milestone 2).
- For scanners (Milestone 5): Docker images for ZAP, Semgrep, Trivy.
The pages in this learning path
| Page | What it's for | When to open it |
|---|---|---|
| This roadmap | The plan and self-checks | At the start of each milestone |
| Security cheat sheet | Learn each idea, with real Juice Shop results | The "learn" step |
| Milestones & Mini-Projects | Tasks, expected results, answer keys | The "test" and "check" steps |
| Quick Reference | Checklists, payloads, scanner commands, templates | Any time |
| Best Practices | Safe, legal, useful habits | After Milestone 1, then every engagement |
| Security testing guide | The service and penetration-test phases | For the deeper "why" |
The milestones
| Milestone | You learn | You work on | Rough time |
|---|---|---|---|
| 1 | Scope, headers, errors, baseline | Recon + baseline on Juice Shop | 1 week |
| 2 | Injection, SQLi | Login bypass + search SQLi | 1–2 weeks |
| 3 | Broken access control, auth | BOLA, JWT, brute force | 1–2 weeks |
| 4 | XSS, business logic | Reflected/stored XSS, price/coupon abuse | 1–2 weeks |
| 5 | Scanners in CI (ZAP, SAST, SCA, secrets) | An automated pipeline | 1 week |
| 6 | CVSS, reporting, a full assessment | A findings report | 1–2 weeks |
Times assume about 5 hours a week.
For each milestone: learn (cheat-sheet sections) → test (the tasks) → check (answer key) → commit your findings and scripts.
Milestone 1: Recon & baseline
Learn: Permission & scope · What security testing is · Think like an attacker · OWASP Top 10 · Security headers · Reading errors · Baseline checks
Work on: Recon + baseline
Then read: Best Practices, sections 1–2.
Check yourself:
- What must you have before testing any real system?
- Which two security headers is Juice Shop missing?
- Why is a 500 with a SQL error a finding on its own?
Milestone 2: Injection
Learn: HTTP & auth recap · Injection & SQLi · Quick Reference: Safe test inputs
Work on: Login bypass + search SQLi
Check yourself:
- Why does
' OR 1=1--log you in as admin? - What is the real fix for SQLi?
- How do you spot a SQLi point without breaking anything?
Milestone 3: Access control & auth
Learn: Broken access control · Authentication · Quick Reference: curl recipes, JWT
Work on: BOLA, JWT, brute force
Then read: Best Practices, sections 6–7.
Check yourself:
- What is BOLA/IDOR, and how do you test for it?
- What's in a JWT payload, and is it encrypted?
- Why test with two accounts per role?
Milestone 4: XSS & business logic
Learn: XSS · Business logic · Common mistakes
Work on: XSS + price/coupon abuse
Check yourself:
- What's the difference between reflected and stored XSS?
- Which header reduces XSS impact — and does Juice Shop set it?
- Why can't a scanner find business-logic flaws?
Milestone 5: Scanners in CI
Learn: Secrets in code · Vulnerable dependencies · Automated scanning (ZAP) · SAST & dependency scans in CI · Quick Reference: Scanner commands
Work on: An automated pipeline
Then read: Best Practices, sections 3–5.
Check yourself:
- What's the difference between a ZAP baseline and full scan?
- Why gate CI on new HIGH/CRITICAL only?
- Why must a leaked secret be rotated, not just deleted?
Milestone 6: Assessment & report
Learn: Burp Suite · API & cloud · CVSS & severity · Reporting · Quick Reference: CVSS, Finding template
Work on: A findings report
Then read: Best Practices, sections 8–11.
Check yourself:
- What makes a finding "Critical"?
- What goes in the first page of a report?
- When do you report a critical, and how?
When you get stuck
| Problem | What to do |
|---|---|
| Juice Shop won't start | Check the port (-p 3001:3000); docker logs juice; wait ~30 s for it to boot |
| A challenge won't solve | Open /#/score-board; Juice Shop has hints and an official companion guide ("Pwning OWASP Juice Shop") |
| A scanner floods you with findings | Filter to HIGH/CRITICAL; confirm by hand before believing |
| Not sure if something's a bug | Ask: could an attacker gain access, data, or control? If unclear, log it as info |
What's next
- API-specific security: API testing cheat sheet.
- Cloud and infrastructure: AWS and Terraform guides.
- Certifications: PortSwigger BSCP, eJPT, OSCP; ISTQB Security Tester (CT-SEC).
Good resources: OWASP Top 10, WSTG and Cheat Sheet Series; the free PortSwigger Web Security Academy; the book The Web Application Hacker's Handbook.