top of page
Web Application Pentester
Who Should Attend?
Pentesters

The Web Application Pentester path is for junior pentesters, AppSec engineers, and developers who already know HTTP basics and want a full web-engagement workflow. You map HTTP and WebSockets with Burp Suite, exploit SQLi, XSS, IDOR, LFI, and CSRF, then move into SSRF, XXE, deserialization, and SSTI. Later units cover REST and business-logic abuse (OpenAPI recon, auth oracles, CORS, JWT, races) and turning a foothold into remote code execution through uploads, command injection, and LFI chains. Five modules.
bottom of page




