This document summarizes Radu State's tutorial on hacking web applications at the 2nd ISSNSM conference. The tutorial covered reconnaissance techniques like DNS interrogation and Whois lookups. It also discussed exploiting vulnerabilities in web servers, weak application configurations, and input validation flaws. Specific hacking methods covered included directory traversal, SQL injection, cross-site scripting, and session hijacking. The document emphasized the importance of ethics in penetration testing.