Web Application Penetration Tester

Introduction to web app security testing

Web enumeration & Information gathering

Web proxies

XSS attacks

SQL injection attacks

Testing for common attacks

File & Resource Attacks

Web service security testing

CMS security testing

Encoding, filtering & evasion basics

For brute forcing login pages start with this: usr/share/wordlists/metasploit/unix_password.txt because it contains default passwords.