Catalog
Web Securitybeginner
Web Application Penetration Testing
A practical, hands-on path from HTTP fundamentals to real vulnerability classes.
9 modules37 lessons13h
#web#burp-suite#owasp
What you'll learn
- Map a web application's full attack surface from HTTP fundamentals up
- Find and exploit SQL injection, XSS, and command injection end to end
- Break weak authentication and session handling, including MFA bypass techniques
- Identify and exploit broken access control, including IDOR and business logic flaws
- Exploit SSRF to reach internal services and abuse cloud metadata endpoints
- Exploit insecure file upload and deserialization vulnerabilities for remote code execution
- Test REST and GraphQL APIs for broken object-level authorization and other API-specific flaws
- Exploit CSRF, CORS misconfigurations, and JWT vulnerabilities
- Write a web application pentest report a development team can actually act on
Who this course is for
Developers, IT staff, and aspiring pentesters who want a practical, hands-on introduction to finding and exploiting real web application vulnerabilities.
Learn to find and report real web application vulnerabilities the way working pentesters do: understand the protocol, map the attack surface, then work systematically through the vulnerability classes that show up in almost every engagement, injection, broken authentication, broken access control, SSRF, insecure file handling, API-specific flaws, and the modern client-side attack surface (CSRF, CORS, JWT). Every lesson pairs the underlying concept with the request/response detail you actually need to exploit and explain it, and every attack class gets a hands-on lab.
Curriculum
Course content
01HTTP Fundamentals & Recon
4 lessons- Anatomy of an HTTP Request8m
- Mapping the Attack Surface10mEnroll to view
Reviews
No reviews yet.