Home / Courses / Web Application Penetration Testing
Cybersecurity · Intermediate

Web Application Penetration Testing

Find and exploit real vulnerabilities in modern web apps — then learn to fix them.

⏱ 24 hours ▤ 42 lessons ◎ 2 enrolled ✦ Certificate on completion

About this course

Web applications are where most breaches begin, and this course puts you on the offensive side of the keyboard. You will work through a purpose-built lab of deliberately vulnerable applications, hunting the flaws that matter in 2026: broken access control, injection, SSRF, insecure deserialization and authentication bypasses.

Every module pairs a short concept video with a hands-on lab. You do not just read about SQL injection — you extract a database with it, then patch the query. By the end you will be able to run a structured web application assessment and write a professional report.

This is an intermediate course: you should be comfortable with HTTP and a little scripting. No prior security experience is required.

Syllabus

01 Recon & mapping the attack surface 5 lessons · 55 min
02 Broken access control & IDOR 6 lessons · 70 min
03 Injection: SQL, NoSQL & command 7 lessons · 85 min
04 Authentication & session attacks 6 lessons · 65 min
05 SSRF, XXE & deserialization 6 lessons · 75 min
06 Reporting & remediation 4 lessons · 40 min

Your instructor

YA
Lead Offensive Security Instructor

OSCP- and OSWE-certified penetration tester. Yousef has led red-team engagements for banks and telcos across Kuwait and the UAE, and teaches offensive security the way it is actually practised — hands on keyboard, against real targets in the lab.

Course materials

Web Application Penetration Testing — syllabus (PDF) Download ↓
Web Application Penetration Testing — lab pack (PDF) Enroll to unlock