In this chapter, we will cover the following recipes: Getting started with web app security testing Using Burp Suite Using OWASP ZAP Exploiting command injection Exploiting XSS Exploiting CSRF