Course Overview

The "OWASP Top 10 Demystified" course is an essential guide for developers, security professionals, and ethical hackers looking to understand and mitigate the most critical web application vulnerabilities. Centered around the OWASP (Open Web Application Security Project) Top 10 list—a globally recognized standard for web app security risks—this course equips learners with the foundational and practical knowledge necessary to protect digital assets in today’s threat landscape. Understanding these vulnerabilities is crucial in reducing exposure to common attacks such as injection flaws, broken authentication, and cross-site scripting (XSS), among others.

This course begins with an introduction to classic web vulnerabilities such as command injections and broken authentication using DVWA labs, followed by in-depth sections on sensitive data exposure, XXE, and insecure deserialization. Learners will explore practical prevention techniques from a developer’s perspective and take a deep dive into advanced XXE and XSS techniques. The course continues by analyzing the OWASP Mobile Top 10 and API Top 10 security risks, including improper platform use, insecure storage, insufficient cryptography, and API asset management. Learners also gain hands-on experience through Postman-based API hacking demos and a range of real-world attack demonstrations covering injection flaws, misconfigurations, and more.

The course delivers hands-on, end-to-end coverage of OWASP’s web, mobile, and API risks, arming learners with real techniques and tools to secure modern digital applications.

What You Will Learn

  • Learn about the top 10 web vulnerabilities of 2017
  • Understand The OWASP top 10 in an understandable manner
  • Learn how to ethically check and implement defenses against the OWASP top 10

Program Curriculum

  • A1.2017 Injections
  • DVWA-Command Injection
  • $7 Million Cybersecurity Scholarship by EC-Council
  • Chapter 01 Quiz

  • A2.2017_broken_authentication
  • DVWA-broken-authentication
  • $7 Million Cybersecurity Scholarship by EC-Council
  • Chapter 02 Quiz

  • A3.2017 Sensitive Data Exposure
  • $7 Million Cybersecurity Scholarship by EC-Council
  • Chapter 03 Quiz

  • A4.2017 XXE
  • $7 Million Cybersecurity Scholarship by EC-Council
  • Chapter 04 Quiz

  • A5.2017 Broken Access Control
  • $7 Million Cybersecurity Scholarship by EC-Council
  • Chapter 05 Quiz

  • A6.2017 Security Misconfigurations
  • $7 Million Cybersecurity Scholarship by EC-Council
  • Chapter 06 Quiz

  • How Does a Reflected XSS Happen?
  • A7.2017 XSS
  • DVWA-Reflected XSS
  • DVWA-Stored XSS
  • Stored XSS Testing Guide
  • Reflected XSS Testing Guide
  • $7 Million Cybersecurity Scholarship by EC-Council
  • Chapter 07 Quiz

  • A8.2017 Insecure Deserialization
  • $7 Million Cybersecurity Scholarship by EC-Council
  • Chapter 08 Quiz

  • A9.2017 Components with Vulnerabilities
  • $7 Million Cybersecurity Scholarship by EC-Council
  • Chapter 09 Quiz

  • A10.2017 Insufficient Logging and Monitoring
  • $7 Million Cybersecurity Scholarship by EC-Council
  • Chapter 10 Quiz

  • A1. How to Prevent OS Command Injections
  • A1. How to Prevent SQLi
  • A2. How to Prevent Broken Authentication
  • $7 Million Cybersecurity Scholarship by EC-Council
  • Chapter 11 Quiz

  • Intro
  • What is XXE
  • Finding Attack Vectors
  • Exploiting
  • WAFs and Filters
  • $7 Million Cybersecurity Scholarship by EC-Council
  • Tools and Prevention
  • Chapter 12 Quiz

  • XSS Full Beginner Guide
  • Advanced XSS Techniques
  • How to Test for Stored XSS
  • How to Test for Reflected XSS
  • $7 Million Cybersecurity Scholarship by EC-Council
  • Chapter 13 Quiz

  • M1
  • $7 Million Cybersecurity Scholarship by EC-Council
  • Chapter 14 Quiz

  • Video: M2
  • $7 Million Cybersecurity Scholarship by EC-Council
  • Chapter 15 Quiz

  • Video: M3
  • Chapter 16 Quiz

  • Video: M4
  • $7 Million Cybersecurity Scholarship by EC-Council
  • Chapter 17 Quiz

  • Video: M5
  • $7 Million Cybersecurity Scholarship by EC-Council
  • Chapter 18 Quiz

  • Video: M6
  • $7 Million Cybersecurity Scholarship by EC-Council
  • Chapter 19 Quiz

  • OWASP M7. Bad Code Quality
  • $7 Million Cybersecurity Scholarship by EC-Council
  • Chapter 20 Quiz

  • Video: M8: Code Tampering
  • Chapter 21 Quiz

  • M9: Reverse Engineering
  • Chapter 22 Quiz

  • OWASP Mobile M10: Extraneous Functionality
  • Chapter 23 Quiz

  • Video: OWASP API 0 Through 3
  • Video: OWASP API 4 Through 7
  • Video: A8: Injection
  • Video: API9:2019 Improper Assets Management
  • Chapter 24 Quiz

  • API Hacking with Postman Part 1 - Getting the Basics Down
  • API Hacking with Postman Part 2 - importing the API Description
  • API Hacking with Postman Part 3 - Pre-request Scripts, Tests, and Console
  • API Hacking with Postman Part 4 - Getting Dirty with Data Sources
  • Chapter 25 Quiz

  • A1. Injection - Simple Injection
  • A1. Injection - SQLi
  • A1. Injections - XXE
  • A1. Injection - Blind Command Injection
  • A2.2017 - Broken Authenticaton - Demonstated
  • A3.2017 - Sensitive Information Exposure
  • A6.2017 Security Misconfigurations
  • Chapter 26 Quiz
Load more modules

Instructor

Wesley Thijs

He is the XSS Rat, an experienced ethical hacker who stands for quality and who believes knowledge is a building block we can all use to grow bigger than we ever were. As a software test he has a unique skill set that center around logic flaws and IDORs which is not seen very much by other hunters. This gives him the advantage of finding less duplicates and maximizing his chance of finding a vulnerability by picking the correct target and applying the correct test strategy.

Join over 1 Million professionals from the most renowned Companies in the world!

certificate

Fastest Way to Level Up Your Cybersecurity Skills

Invest in your future with flexible subscription plans that give you access to the world’s largest online cybersecurity course library. Whether you're exploring cybersecurity courses for beginners or advancing your expertise,
access in-demand courses, practical labs, and CTF challenges designed to support continuous learning.

Monthly Plans
Annual Plans
Save 20% with our annual plans!

Pro

Build your cybersecurity skills with 900+ bite-sized courses and curated learning paths designed for continuous learning.

$ 69.00
Billed monthly or $599.00 billed annually

What is included

  • 880+ Premium Short Courses
  • 70+ Structured Learning Paths
  • Validation of Completion with all courses and learning paths
  • New Courses added every month
Early Access Offer

Pro +

Develop real-world cybersecurity skills through hands-on labs and CTF challenges designed for practical learning.

$ 79.00
Billed monthly or $699.00 billed annually

Everything in Pro, Plus:

  • 1600+ Hands-on lab exercises with guided instructions
  • 150+ CTF Challenges with detailed walkthroughs
  • New Hands-on Labs and Challenges added every month

Related Courses

1 of 50