<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/"><channel><title>Web Pentest on KevinSec</title><link>https://kevinsec.io/tags/web-pentest/</link><description>Recent content in Web Pentest on KevinSec</description><generator>Hugo</generator><language>en-us</language><lastBuildDate>Wed, 08 Jul 2026 00:00:00 +0000</lastBuildDate><atom:link href="https://kevinsec.io/tags/web-pentest/index.xml" rel="self" type="application/rss+xml"/><item><title>Burp Suite Beginner Workflow for Web Pentest</title><link>https://kevinsec.io/blog/burp-suite-beginner-workflow-for-web-pentest/</link><pubDate>Wed, 08 Jul 2026 00:00:00 +0000</pubDate><guid>https://kevinsec.io/blog/burp-suite-beginner-workflow-for-web-pentest/</guid><description>A practical beginner workflow for using Burp Suite during web pentesting, from proxy setup to Repeater, Intruder, notes, and reporting evidence.</description></item><item><title>Legal Recon for Web Pentesting</title><link>https://kevinsec.io/blog/legal-recon-for-web-pentesting/</link><pubDate>Wed, 08 Jul 2026 00:00:00 +0000</pubDate><guid>https://kevinsec.io/blog/legal-recon-for-web-pentesting/</guid><description>A practical guide to performing legal, scope-aware reconnaissance before a web pentest, without crossing authorization boundaries.</description></item><item><title>Lessons Learned from a Web Pentest Engagement</title><link>https://kevinsec.io/blog/lessons-learned-from-a-web-pentest-engagement/</link><pubDate>Wed, 08 Jul 2026 00:00:00 +0000</pubDate><guid>https://kevinsec.io/blog/lessons-learned-from-a-web-pentest-engagement/</guid><description>Practical lessons from web pentest engagements: scope discipline, recon quality, business logic testing, evidence, reporting, and remediation clarity.</description></item><item><title>Manual Testing vs Automated Scanning</title><link>https://kevinsec.io/blog/manual-testing-vs-automated-scanning/</link><pubDate>Wed, 08 Jul 2026 00:00:00 +0000</pubDate><guid>https://kevinsec.io/blog/manual-testing-vs-automated-scanning/</guid><description>A practical comparison of manual web security testing and automated scanning, including when to use each and why both matter.</description></item><item><title>Authentication Testing Checklist for Web Applications</title><link>https://kevinsec.io/blog/authentication-testing-checklist-for-web-applications/</link><pubDate>Wed, 08 Jul 2026 00:00:00 +0700</pubDate><guid>https://kevinsec.io/blog/authentication-testing-checklist-for-web-applications/</guid><description>A practical authentication testing checklist for web applications.</description></item><item><title>How to Read an HTTP Request Like a Pentester</title><link>https://kevinsec.io/blog/how-to-read-an-http-request-like-a-pentester/</link><pubDate>Wed, 08 Jul 2026 00:00:00 +0700</pubDate><guid>https://kevinsec.io/blog/how-to-read-an-http-request-like-a-pentester/</guid><description>A beginner-friendly guide to reading HTTP requests from a web pentesting perspective.</description></item><item><title>IDOR Explained with a Simple Lab Scenario</title><link>https://kevinsec.io/blog/idor-explained-with-a-simple-lab-scenario/</link><pubDate>Wed, 08 Jul 2026 00:00:00 +0700</pubDate><guid>https://kevinsec.io/blog/idor-explained-with-a-simple-lab-scenario/</guid><description>A beginner-friendly explanation of IDOR using a safe lab scenario.</description></item></channel></rss>