Website Hacking & Security
Learn how real web attacks work — and how to shut them down. This track walks the full offensive chain from authorised recon to exploitation and reporting, then flips to the defensive side: secure coding, headers, session design and supply-chain hardening. Legal labs only, ethics first.
- Lessons
- 12
- Focus
- Red + Blue
- Labs
- Hands-on
- Cost
- Free
What you'll be able to do
- Operate legally and ethically: scope, authorisation and responsible disclosure.
- Map an application's attack surface across HTTP, cookies, sessions and APIs.
- Find and explain reflected, stored and DOM-based XSS — then fix them properly.
- Understand SQL and NoSQL injection, including blind variants, and defend with parameterised queries.
- Break and repair authentication, session handling, MFA and password storage.
- Spot IDOR and privilege escalation, and enforce server-side access control.
- Harden the browser layer with CSP, security headers, TLS and cookie flags.
- Run a full assessment in a legal lab and deliver a professional pentest report.
Who this track is for
- Developers who want to stop shipping exploitable code.
- Aspiring bug bounty hunters and junior pentesters starting from zero.
- Students preparing for security certifications or CTF competitions.
- Founders and tech leads who need to review their own app's security posture.
Lesson overview
- 01Ethical Hacking & The LawAuthorisation, scope, responsible disclosure and legal practice labs.
- 02How The Web Works (Attack Surface)HTTP, requests, cookies, sessions and where bugs actually live.
- 03Reconnaissance & MappingFingerprinting, subdomains, directories and reading the front end.
- 04Cross-Site Scripting (XSS)Reflected, stored and DOM XSS - impact and prevention.
- 05SQL & NoSQL InjectionHow injection works, blind variants and parameterised queries.
- 06Broken Authentication & SessionsCredential attacks, session handling, MFA and password storage.
- 07Broken Access Control & IDORHorizontal and vertical privilege escalation, and server-side checks.
- 08CSRF, SSRF & Open RedirectForged requests, server-side request forgery and unsafe redirects.
- 09Security Headers, TLS & CookiesHardening the transport and browser layer.
- 10API, Secrets & Supply Chain SecurityKeys, rate limits, dependencies and CI/CD risk.
- 11The Tester's Toolkit & MethodologyProxy interception, scanners, fuzzing and a repeatable process.
- 12Capstone: Full Lab Pentest & ReportRun an end-to-end assessment on a legal lab and write the report.
Finish the track, earn the credential
Every lesson is quiz-checked and progress-tracked. Complete the capstone to unlock a collectible skill badge and a verifiable KR0SS Academy certificate.