Course Overview

In this course, it will be shown to you how hackers can?bypass Content Security Policy (CSP) which is the most powerful defensive technology in modern web applications. Then during this course, it will also be demonstrated how?web applications can be hacked via PDFs, images, and links. You will also learn how hackers can steal secrets from AngularJS applications, which are very popular these days.? Before concluding the course, you will understand how to exploit race conditions in web applications and how serious the consequences of this attack can be. 

At the end of this course, you would have gained knowledge about other powerful, full-stack attacks on modern web applications such as HTTP parameter pollution, subdomain takeover, and clickjacking. In this online training, we will show you a lot of demos because we want you to apply this knowledge in your own pentesting projects. You’ll learn step by step how all these attacks work and you’ll also learn how to check if your web applications are vulnerable to these attacks.

What You Will Learn

  • Dive into full-stack exploitation of modern web applications
  • Learn how hackers can bypass Content Security Policy (CSP)
  • Discover how web applications can be hacked via PDFs
  • images
  • and links
  • Explore how hackers can steal secrets from AngularJS applications
  • Check if your web applications are vulnerable to race condition attacks
  • Learn about HTTP parameter pollution
  • subdomain takeover
  • and clickjacking
  • Discover step by step how all these attacks work in practice (DEMOS)

Program Curriculum

  • Introduction
  • Bypassing CSP via ajax.googleapis.com
  • Bypassing CSP via Flash File
  • Bypassing CSP via Polyglot File
  • Bypassing CSP via Angular JS
  • $7 Million Cybersecurity Scholarship by EC-Council
  • Chapter 01 Quiz

  • Introduction
  • Token Hijacking via PDF – Part 1
  • Token Hijacking via PDF – Part 2
  • XSS via Image – Part 1
  • XSS via Image – Part 2
  • User Redirection via window.opener Tabnabbing – Part 1
  • User Redirection via window.opener Tabnabbing – Part 2
  • Chapter 02 Quiz

  • Introduction
  • AngularJS: Template Injection and $scope Hacking – Part 1
  • AngularJS: Template Injection and $scope Hacking – Part 2
  • AngularJS: Going Beyond the $scope
  • AngularJS: Hacking a Static Template
  • Summary – Hacking AngularJS Applications
  • Chapter 03 Quiz

  • Introduction
  • Exploiting Race Conditions – Case 1 (Part 1)
  • Exploiting Race Conditions – Case 1 (Part 2)
  • Exploiting Race Conditions – Case 2
  • Case Studies of Award-Winning Race Condition Attacks
  • Chapter 04 Quiz

  • Introduction
  • HTTP Parameter Pollution – Part 1
  • HTTP Parameter Pollution – Part 2
  • Subdomain Takeover – Part 1
  • Subdomain Takeover – Part 2
  • Account Takeover via Clickjacking – Part 1
  • Account Takeover via Clickjacking – Part 2
  • Chapter 05 Quiz
Load more modules

Instructor

Dawid Czagan

Dawid Czagan (@dawidczagan) is an internationally recognized security researcher and trainer. He is listed among the top hackers at HackerOne. Dawid Czagan has found security vulnerabilities in Google, Yahoo, Mozilla, Microsoft, Twitter and other companies. Due to the severity of many bugs, he received numerous awards for his findings. Dawid Czagan shares his security bug hunting experience in his hands-on trainings “Hacking Web Applications – Case Studies of Award-Winning Bugs in Google, Yahoo, Mozilla and More” and “Black Belt Pentesting / Bug Hunting Millionaire: Mastering Web Attacks with Full-Stack Exploitation”. He delivered security training courses at key industry conferences such as Hack In The Box (Amsterdam), CanSecWest (Vancouver), 44CON (London), Hack In Paris (Paris), DeepSec (Vienna), NorthSec (Montreal), HITB GSEC (Singapore), BruCON (Ghent) and for many corporate clients. His students include security specialists from Oracle, Adobe, ESET, ING, Red Hat, Trend Micro, Philips and the government sector (references are attached to Dawid Czagan's LinkedIn profile (https://www.linkedin.com/in/dawid-czagan-85ba3666/). They can also be found here: https://silesiasecuritylab.com/services/training/#opinions). Dawid Czagan is the founder and CEO of Silesia Security Lab – a company which delivers specialized security testing and training services. He is also an author of online security courses. To find out about the latest in Dawid Czagan’s work, you are invited to subscribe to his newsletter (https://silesiasecuritylab.com/newsletter) and follow him on Twitter (@dawidczagan) and LinkedIn (https://www.linkedin.com/in/dawid-czagan-85ba3666/).

Join over 1 Million professionals from the most renowned Companies in the world!

certificate

Empower Your Learning with Our Flexible Plans

Invest in your future with our flexible subscription plans. Whether you're just starting out or looking to enhance your expertise, there's a plan tailored to meet your needs. Gain access to in-demand skills and courses for your continuous learning needs.

Monthly Plans
Annual Plans
Save 20% with our annual plans!

Pro

Ideal for continuous learning, offering extensive resources with 600+ courses and diverse Learning Paths to enhance your skills.

$ 499.00
Billed annually or $59.00 billed monthly

What is included

  • 700+ Premium Short Courses
  • 50+ Structured Learning Paths
  • Validation of Completion with all courses and learning paths
  • New Courses added every month
Early Access Offer

Pro +

Experience immersive learning with Practice Labs, CTF Challenges, and exclusive EC-Council certifications for comprehensive skill-building.

$ 599.00
Billed annually or $69.00 billed monthly

Everything in Pro and

  • 800+ Practice Lab exercises with guided instructions
  • 150+ CTF Challenges with detailed walkthroughs
  • New Practice Labs and Challenges added every month
  • 3 Official EC-Council Essentials Certifications¹ (retails at $897!)
    Exclusive Bonus with Annual Plans

¹This plan includes Digital Forensics Essentials (DFE), Ethical Hacking Essentials (EHE), and Network Defense Essentials (NDE) certifications. No other EC-Council certifications are included.

Related Courses

1 of 8