top of page

Web Application Pentester

Who Should Attend?

Pentesters

Web Application Pentesting

The Web Application Pentester path is for junior pentesters, AppSec engineers, and developers who already know HTTP basics and want a full web-engagement workflow. You map HTTP and WebSockets with Burp Suite, exploit SQLi, XSS, IDOR, LFI, and CSRF, then move into SSRF, XXE, deserialization, and SSTI. Later units cover REST and business-logic abuse (OpenAPI recon, auth oracles, CORS, JWT, races) and turning a foothold into remote code execution through uploads, command injection, and LFI chains. Five modules.

web pentesting fundamentals

Web Pentesting Fundamentals

Intermediate

6 Hours

core vulnerability exploitation

Core Vulnerability Exploitation

Intermediate

8 Hours

advanced web vulnerabilities

Advanced Web Vulnerabilities

Intermediate

8 Hours

apis and business logic abuse

APIs and Business Logic Abuse

Intermediate

8 Hours

remote code execution

From Foothold to Remote Code Execution

Intermediate

6 Hours

StartLearning
bottom of page