Course Overview

Web application penetration testing is an essential cybersecurity discipline that helps organizations identify and remediate vulnerabilities before attackers can exploit them. As modern web applications continue to grow in complexity, security professionals must understand how to assess applications, simulate real-world attacks, and implement effective countermeasures. This course provides practical, hands-on experience in discovering, exploiting, and mitigating common web application vulnerabilities using industry-standard tools and techniques.

This course begins with building a secure penetration testing lab using VirtualBox, Kali Linux, and intentionally vulnerable web applications. You will then explore reconnaissance techniques, file upload vulnerabilities, and remote code execution before progressing to common web application attacks, including SQL injection, Cross-Site Scripting (XSS), Remote File Inclusion (RFI), and Cross-Site Request Forgery (CSRF). The course also covers practical use of industry-standard tools such as Burp Suite, sqlmap, BeEF, and OWASP ZAP for vulnerability discovery, exploitation, and security automation. Advanced topics include password attacks, CMS security assessment, and automated web application testing to simulate real-world penetration testing engagements.

By the end of this course, you will be able to identify, exploit, assess, and mitigate common web application vulnerabilities while using professional penetration testing tools to strengthen the security of modern web applications.

What You Will Learn

  • Understand the basics of Kali Linux.
  • Learn more about file upload, code execution, local file inclusion, and remote file inclusion vulnerabilities and how to tackle them.
  • Explore SQL Injection, Advanced SQLI, XXS, BeEF Framework, and CSRF.
  • Learn about the different password attacks.

Program Curriculum

  • Introduction
  • $7 Million Cybersecurity Scholarship by EC-Council

  • Building Lab Concepts
  • Building a Lab VirtualBox
  • Deploying a Kali Linux VM
  • Deploying a Metasploitable VM
  • Deploying Windows VM
  • Chapter 2 Quiz

  • Kali Linux Overview
  • Linux Command Line Overview
  • Lab Network and Metasploitable Settings
  • Websites 101
  • Web Hacking Intro
  • Chapter 3 Quiz

  • Information Gathering
  • Discovery Tools
  • DNS Reconnaissance
  • Websites Same Server
  • Subdomains
  • Files Directories
  • Analyzing Discovered Files 1
  • Maltego 1of2
  • Maltego Part 2-1
  • Chapter 4 Quiz

  • Introduction File Upload Vulnerability
  • HTTP Requests
  • Using Burp as Proxy
  • Exploiting Advanced File Upload Vulnerability
  • Exploiting More Advanced File Upload Vulnerability
  • Security File Upload Vuln
  • Chapter 5 Quiz

  • Code Exec Vuln
  • Advabced Code Execution Vulnerabilities
  • Security Code Exec Vuln
  • Chapter 6 Quiz

  • Local File Vulnerabilities
  • Get Shell from LFI
  • Get Shell from LFI Part 2
  • Chapter 7 Quiz

  • Remote File Inclusion Vulnerabilities (1 of 3)
  • Remote File Inclusion Vulnerability (2 of 3)
  • Remote File Inclusion Vulnerability (3 of 3)
  • RFI Vulnerability Countermeasures
  • Chapter 8 Quiz

  • SQL Injection
  • SQLi
  • Chapter 9 Quiz

  • SQLi on https post
  • Bypassing Logins using SQL Injection
  • Bypassing More Secure Logins using SQL Injection
  • Mitigating SQL Injection Login Bypassing
  • Chapter 10 Quiz

  • Discovering SQL Injection in GET
  • Reading Database Information
  • Find Database Tables
  • Extracting Sensitive Information Such as Passwords
  • Chapter 11 Quiz

  • Exploiting Blind SQL Injections
  • Discovering More Complex SQL Injections
  • Extracting Passwords Using a More Complex SQL Injection
  • Bypassing Security and Accessing All Records
  • Bypassing Filters
  • Quick Fix to Prevent SQL Injections
  • Reading and Writing Files on The Server Using SQL Injection
  • Getting Reverse Shell and Full Control of a Web Server
  • SQLmap
  • Getting a Direct SQL Shell Using SQLmap
  • Security SQLi
  • Chapter 12 Quiz

  • Introduction XSS
  • Reflected XSS
  • Discovering Advanced Reflected XSS
  • More Advanced Reflected XSS
  • Stored XSS
  • Discovering Advanced Stored XSS
  • DOM Based XSS
  • Chapter 13 Quiz

  • Beef XSS
  • Hooking Victims to BeEF using Stored XSS
  • BeEF Interacting with Hooked Victims
  • BeEF Running Basic Commands on Victims
  • BeEF Stealing Credentials from a Fake Login Prompt
  • Installing Veil
  • Veil Overview and Basic Payloads
  • Generating an Undetectable Backdoor Using Veil 3
  • Listening for Incoming Connections
  • Basic Backdoor Delivery Method
  • BeEF Gaining Full Control over Windows Target
  • Security Tips for XSS
  • Chapter 14 Quiz

  • Loggin In as Admin without Password Manipulating Cookies
  • Discovering CSRF Vulnerabilities
  • Exploiting CSRF Vulnerability to Change Admin Password Using HTML File
  • Exploiting CSRF 2 of 2
  • Security Tips to Prevent CSRF
  • Chapter 15 Quiz

  • Brute Force and Dictionary Attacks
  • Creating a Wordlist
  • Hydra Part 1 of 2
  • Launching a Wordlist Attack with Hydra part 2 1
  • Chapter 16 Quiz

  • OWASP ZAP
  • Analyzing Scan Results with OWASP ZAP
  • w3af console1
  • Acunetix1
  • wmap 1
  • csmap1
  • xml injection 1
  • Chapter 17 Quiz

Conclusion

Load more modules

Instructor

Luciano Ferrari

Chief Executive Officer of the IT security and data defense firm Cyology Labs™ in Montréal, Canada

Luciano Ferrari is an information security leader and IoT hacking expert. He holds multiple security certifications, including CISSP, CISM, CRISC, and PCIP, and has worked at Fortune 500 companies in both technical and leadership roles. He drives progress at his own company, LufSec, where he works on security-related issues and projects. Luciano has conducted hundreds of IT security audits and penetration tests, including audits and tests on IoT devices for cable companies. He has also leveraged his IT security expertise in manufacturing, semiconductor, financial, and educational institutions. With his background in electronics and microelectronics, his distinct specialization is definitely on hardware hacking. Luciano is passionate about sharing his knowledge with others and teaching. His other areas of expertise include IT infrastructure, networking, penetration testing, risk, vulnerability, and threat management. In private, he enjoys researching new technologies and participating at security conferences and in bug bounty programs.

Join over 1 Million professionals from the most renowned Companies in the world!

certificate

Fastest Way to Level Up Your Cybersecurity Skills

Invest in your future with flexible subscription plans that give you access to the world’s largest online cybersecurity course library. Whether you're exploring cybersecurity courses for beginners or advancing your expertise,
access in-demand courses, practical labs, and CTF challenges designed to support continuous learning.

Monthly Plans
Annual Plans
Save 20% with our annual plans!

Pro

Build your cybersecurity skills with 900+ bite-sized courses and curated learning paths designed for continuous learning.

$ 69.00
Billed monthly or $599.00 billed annually

What is included

  • 880+ Premium Short Courses
  • 70+ Structured Learning Paths
  • Validation of Completion with all courses and learning paths
  • New Courses added every month
Early Access Offer

Pro +

Develop real-world cybersecurity skills through hands-on labs and CTF challenges designed for practical learning.

$ 79.00
Billed monthly or $699.00 billed annually

Everything in Pro, Plus:

  • 1600+ Hands-on lab exercises with guided instructions
  • 150+ CTF Challenges with detailed walkthroughs
  • New Hands-on Labs and Challenges added every month

Related Courses

1 of 50