// layer8 / domains
Domains
Eight areas the club works across. Pick one to see the attack surface, the tools, and a rough path from zero to research — break things responsibly.
// domain dossier
$ cd ~/domains/web
$ cat README.md
Web Exploitation
Map how a web application handles identity, input and data before testing where those boundaries fail.
$ ./explore --topics
→ OWASP Top 10
→ XSS
→ SQLi
→ SSRF
→ Auth
$ suggested_path
Request mapping -> input testing -> impact proof
Request mapping -> input testing -> impact proof
// learning roadmap
// tools
- Burp Suite
- ffuf
- SQLMap
// what_you_learn
// projects
Web security labs & CTF challenges
Not sure which one?
Most people try a few before something sticks. Bring an unsolved challenge to a weekly session and pick a lane from there.
