Purpose Manual HTTP testing: intercept, modify, replay requests; identify common input issues (XSS, SQLi, auth flaws) on lab apps. Subtopics • Interception: Burp Suite / mitmproxy setup & proxying browser traffic • Manual workflow: identify input points → Repeater → Replay → document evidence • Simple XSS verification (reflected/stored) and safe payloads (lab only) • SQLi enumeration with sqlmap (non-destructive options) • Endpoint discovery & fuzzing: wfuzz/wordlists, nikto for quick checks • Reporting: request/response captures, payloads used, remediation suggestions