For the purpose of the owasp testing guide, only the security threats related to web applications will be considered and not threats to web servers (e.g., the infamous “%5c escape code” into microsoft iis web server). further reading suggestions will be provided in the references section for interested readers.