About
Prerequisite: Complete [Web Applications 101](https://www.darkrelay.com/challenge-page/web-applications-101) before this module. You should already be comfortable with HTTP request/response mechanics, frontend/backend architecture, and browser security headers (CORS, CSP) before you intercept NeonVault traffic in Burp Suite. In this module of the Web Application Pentester learning path, you will build the web pentesting fundamentals required to systematically audit modern web applications. You will move away from relying on automated scanners and learn how to map, manipulate, and intercept raw web traffic using industry-standard tools like Burp Suite. This module introduces the language of the web (HTTP, statelessness, sessions, cookies, and WebSockets) and pairs this technical understanding with professional methodologies. You will explore the OWASP Top 10 risk categories, practice a short reconnaissance pass for information disclosure on NeonVault, and learn how to map findings to the OWASP Application Security Verification Standard (ASVS) and Web Security Testing Guide (WSTG). By the end of this module, you will understand how to structure a penetration test, capture and modify traffic, and write actionable, framework-aligned vulnerability reports. Upon completion of the module, students will be able to: - Understand the architecture of modern web applications and the HTTP protocol. - Intercept, modify, and replay HTTP and WebSocket traffic using Burp Suite Community Edition. - Perform baseline recon and document common information-disclosure signals on a live target. - Categorize vulnerabilities according to the OWASP Top 10. - Use the OWASP ASVS to provide strict remediation guidance to developers. - Use the OWASP WSTG to ensure a thorough, repeatable testing methodology. For inquiries, please write us at https://www.darkrelay.com/cybersecurity-course-inquiry
Overview
Acceptable Usage Policy
.1 step
Lab Access
.1 step
Web Pentesting Fundamentals
.9 steps