Skip to main content
The Cyber Security: ethical hacking and cyber security training, Canada
Core

Web Application Penetration Testing

This web application penetration testing course takes you from mapping an unfamiliar application to exploiting real flaws and reporting them clearly. You test only applications we host in the academy lab, under a written scope and rules of engagement.

You work through the Open Web Application Security Project, or OWASP, Top 10 and well beyond it: injection, broken access control, authentication flaws, server-side request forgery and business logic abuse, then write findings a development team can reproduce and fix.

Duration
8 weeks
Format
Live online, instructor-led
Prerequisites
None required
Class size
Capped at 12 learners
Web Application Penetration Testing

What you will be able to do

  • Scope a web application test and agree rules of engagement before you start
  • Map an unfamiliar application and catalogue its attack surface
  • Find and exploit OWASP Top 10 vulnerabilities in a controlled lab
  • Test REST and GraphQL APIs for authorization and input flaws
  • Rate findings with the Common Vulnerability Scoring System, or CVSS
  • Write a reproducible finding a developer can confirm and fix
  • Retest a fix and confirm the vulnerability is closed

Course outline

5 modules

  • Scoping and rules of engagement for web tests
  • Content discovery and spidering
  • Identifying frameworks and technologies
  • Building a request baseline with an intercepting proxy

What you need before you start

  • Working knowledge of how HTTP and web applications behave
  • Some familiarity with HTML and at least one programming language
  • A laptop able to run a browser and an intercepting proxy

Who this course is for

  • Penetration testers focusing on web and API targets
  • Developers who want to find flaws before attackers do
  • Security analysts adding application testing to their skills
  • Professionals preparing for the EC-Council CEH exam

Where this leads

Prepares you for

CEH

Awarded by EC-Council

The EC-Council Certified Ethical Hacker credential is awarded by EC-Council once you pass their exam, not by the academy. This course builds the web testing skills the CEH covers and gives you the hands-on practice the exam style rewards.

Questions about this course

Ready to launch your cyber security career?

Join the next live online cohort. No experience required, just bring the curiosity.