AcademyOFFENSE / DEFENSE
Web Security Tutorial
Ethical website hacking and defence: recon, XSS, SQL injection, CSRF, broken authentication, access control, security headers, secure coding and a lab-based pentest report capstone.
0/12 lessons complete
- 01Ethical Hacking & The LawAuthorisation, scope, responsible disclosure and legal practice labs.
- 02How The Web Works (Attack Surface)HTTP, requests, cookies, sessions and where bugs actually live.
- 03Reconnaissance & MappingFingerprinting, subdomains, directories and reading the front end.
- 04Cross-Site Scripting (XSS)Reflected, stored and DOM XSS - impact and prevention.
- 05SQL & NoSQL InjectionHow injection works, blind variants and parameterised queries.
- 06Broken Authentication & SessionsCredential attacks, session handling, MFA and password storage.
- 07Broken Access Control & IDORHorizontal and vertical privilege escalation, and server-side checks.
- 08CSRF, SSRF & Open RedirectForged requests, server-side request forgery and unsafe redirects.
- 09Security Headers, TLS & CookiesHardening the transport and browser layer.
- 10API, Secrets & Supply Chain SecurityKeys, rate limits, dependencies and CI/CD risk.
- 11The Tester's Toolkit & MethodologyProxy interception, scanners, fuzzing and a repeatable process.
- 12Capstone: Full Lab Pentest & ReportRun an end-to-end assessment on a legal lab and write the report.