Masterclass: Web Application Pentesting - english - virtual



Kursarrangør: Glasspaper AS
Sted: Nettkurs / Nettstudie
Hele landet
Type:Nettkurs og nettstudie
Studie / yrkesutdanning
Undervisningstid: kl 09:00 - 16:00
Varighet: 4 days
Pris: 34.900
Neste kurs: 12.10.2026 | Vis alle kursdatoer

We provide virtual course about Masterclass: Web Application Pentesting in english. In this 3-day, 21-hour course, you will develop essential cybersecurity knowledge and skills with a focus on Web Application Pentesting.

Moreover, you will be able to:
• Get the highest quality and unique learning experience - the class is limited to 16 participants by default
• Get the opportunity to interact with our world-renowned Experts
• Go through CQURE’s custom lab exercises and practice them after the course
• Receive a lifelong certification after completing the course
• Get 12-month access to the recordings

Why this course:
This course covers techniques and strategy concepts for performing professional web applications penetration testing in a highly secure environment. Our course has been developed around professional penetration testing, web applications development and security awareness in the business and IT fields.

Our goal is to show you all the most important aspects of web application penetration testing. Together we will look for vulnerabilities and exploit them in practice in CQURE’s custom-built training environment. During the exercises, we will use industry-standard tools such as the Kali Linux, Burp Suite, Bloodhound, Metasploit and the Wireshark.

Course outline:
The Web Application Pentesting agenda consists of 10 modules that will be covered during 3 days. The training will allow you to understand the penetration tester’s perspective on security, and learn crucial tools and concepts needed for everyone considering developing their career in penetration testing or cybersecurity in general.

Agenda:
Module 1 - Introduction to Web Penetration Testing:
• What is Penetration Testing
• Cyber Kill Chain
• MITRE ATT&CK Matrix
• Testing methodologies
• Reporting

Module 2 - Reconnaissance:
• Open-Source Intelligence (OSINT)
• Google hacking and alternative search engines
• Subdomains and DNS enumeration
• Discovering hidden secrets

Module 3 - Introduction to Web Application testing:
• OWASP TOP 10
• Role of local-proxy
• Work automatization
• Business logic issues
• Supply chain attacks and vulnerable components
• Chaining security issues
• Information disclosures

Module 4 - Browser's security mechanisms:
• Same Origin Policy
• CORS and other exceptions
• 3rd party cookies
• Security headers
• Content Security Policy (CSP)
• Cookies’ and local storage security

Module 5 - Cross Site Scripting:
• Reflected and Stored Cross Site Scripting
• Attacking Document Object Model
• Bypassing weak CSP

Module 6 - Injections:
• Blacklisting vs whitelisting
• SQL injections
• Command injections
• Other injection attacks

Module 7 - Authentication and Authorization:
• Attacks on authentication and authorization
• Attacks on sessions
• Insecure Direct Object Reference (IDOR) attacks
• Default credentials
• JSON Web Tokens

Module 8 - Insecure file handling:
• Path traversal
• Content manipulation
• Insecure file extensions

Module 9 - Insecure inclusions:
• Local File Inclusion
• Remote File Inclusion

Module 10 - Testing API:
• OWASP Top 10 for API
• Bypassing API access controls
• Mass assignment attacks

Target audience:
This bootcamp is designed for you if you are a:
• Penetration tester
• Security analyst
• IT administrator
• Cybersecurity professional
• & a geek with IT background who wants to start an adventure in the cybersecurity pentesting field

Language:
• English course material, english speaking instructor

Course material:
The course fee includes lab exercises, course materials and certification

Certification:
After finishing the course, you will be granted a CQURE Certificate of Completion. Please note that after completing the course you will also be eligible for CPE points!