Injection & Browser Testing
Exercise every WSHawk injection family against paired secure and vulnerable controls, verify browser execution, and tune scanner confidence.
Do the work in order.
- 0155 min↗
Test SQL injection
Compare parameterized search with an intentional string-concatenation flaw using error and boolean probes.
- 0270 min↗
Verify reflected and DOM XSS
Separate reflection from execution and use WSHawk's isolated Playwright verifier for the DOM sink.
- 0365 min↗
Test command and NoSQL injection
Use WSHawk markers to reveal shell concatenation and document-query operator injection.
- 0465 min↗
Test path traversal, LFI, and XXE
Exercise filesystem normalization and external-entity controls without accessing a real system file or network service.
- 0555 min↗
Test SSRF with local OAST
Prove destination filtering and blind-callback evidence using a local interaction ledger.
- 0655 min↗
Test prototype pollution and open redirect
Inspect dangerous object keys and redirect destinations with deterministic marker payloads.
- 0760 min↗
Tune the scanner, payload evolution, and CVSS
Control scan scope, Smart Payload Evolution, confidence, duplicates, and scoring across the complete injection catalogue.
