Academy
OFFENSE / DEFENSE

Web Security Tutorial

Ethical website hacking and defence: recon, XSS, SQL injection, CSRF, broken authentication, access control, security headers, secure coding and a lab-based pentest report capstone.

0/12 lessons complete

  1. 01Ethical Hacking & The LawAuthorisation, scope, responsible disclosure and legal practice labs.
  2. 02How The Web Works (Attack Surface)HTTP, requests, cookies, sessions and where bugs actually live.
  3. 03Reconnaissance & MappingFingerprinting, subdomains, directories and reading the front end.
  4. 04Cross-Site Scripting (XSS)Reflected, stored and DOM XSS - impact and prevention.
  5. 05SQL & NoSQL InjectionHow injection works, blind variants and parameterised queries.
  6. 06Broken Authentication & SessionsCredential attacks, session handling, MFA and password storage.
  7. 07Broken Access Control & IDORHorizontal and vertical privilege escalation, and server-side checks.
  8. 08CSRF, SSRF & Open RedirectForged requests, server-side request forgery and unsafe redirects.
  9. 09Security Headers, TLS & CookiesHardening the transport and browser layer.
  10. 10API, Secrets & Supply Chain SecurityKeys, rate limits, dependencies and CI/CD risk.
  11. 11The Tester's Toolkit & MethodologyProxy interception, scanners, fuzzing and a repeatable process.
  12. 12Capstone: Full Lab Pentest & ReportRun an end-to-end assessment on a legal lab and write the report.