Web Application Penetration Testing
This web application penetration testing course takes you from mapping an unfamiliar application to exploiting real flaws and reporting them clearly. You test only applications we host in the academy lab, under a written scope and rules of engagement.
You work through the Open Web Application Security Project, or OWASP, Top 10 and well beyond it: injection, broken access control, authentication flaws, server-side request forgery and business logic abuse, then write findings a development team can reproduce and fix.
- Duration
- 8 weeks
- Format
- Live online, instructor-led
- Prerequisites
- None required
- Class size
- Capped at 12 learners

What you will be able to do
- Scope a web application test and agree rules of engagement before you start
- Map an unfamiliar application and catalogue its attack surface
- Find and exploit OWASP Top 10 vulnerabilities in a controlled lab
- Test REST and GraphQL APIs for authorization and input flaws
- Rate findings with the Common Vulnerability Scoring System, or CVSS
- Write a reproducible finding a developer can confirm and fix
- Retest a fix and confirm the vulnerability is closed
Course outline
5 modules
- Scoping and rules of engagement for web tests
- Content discovery and spidering
- Identifying frameworks and technologies
- Building a request baseline with an intercepting proxy
What you need before you start
- Working knowledge of how HTTP and web applications behave
- Some familiarity with HTML and at least one programming language
- A laptop able to run a browser and an intercepting proxy
Who this course is for
- Penetration testers focusing on web and API targets
- Developers who want to find flaws before attackers do
- Security analysts adding application testing to their skills
- Professionals preparing for the EC-Council CEH exam
Where this leads
Prepares you for
CEH
Awarded by EC-Council
The EC-Council Certified Ethical Hacker credential is awarded by EC-Council once you pass their exam, not by the academy. This course builds the web testing skills the CEH covers and gives you the hands-on practice the exam style rewards.
Questions about this course
More in offensive security
Ready to launch your cyber security career?
Join the next live online cohort. No experience required, just bring the curiosity.



