Kurskode: CQ-WAP

varighet: 3 Dag(er)

Sted: Virtual, Instructor Led Training
Katergori: CQURE Academy

Course Overview

Develop essential cybersecurity knowledge and skills with a focus on Web Application Pentesting

This course covers techniques and strategy concepts for performing professional web applications penetration testing in a highly secure environment.

It has been developed around professional penetration testing, web applications development and security awareness in the business and IT fields.

The course will start by reviewing the key aspects of penetration testing – both in terms of methodologies and legal aspects and reporting.

During the course, you will learn advanced reconnaissance techniques, which will allow to professionally prepare for a penetration test. After discussing the OWASP Top 10, you will deep-dive into web browser security mechanisms, vulnerability exploitations, injections, bypassing API controls and many more valuable skills.

Our goal is to show you all the most important aspects of web application penetration testing.

Together we will look for vulnerabilities and exploit them in practice in CQURE’s custom-built training environment. During the exercises, we will use industry-standard tools such as the Kali Linux, Burp Suite, Bloodhound, Metasploit and the Wireshark.

Updated Feb2026

  1. • Module 1: Introduction to Penetration Testing
    1. • What is Penetration Testing
    2. • Cyber Kill Chain
    3. • MITRE ATT&CK Matrix
    4. • Testing methodologies 
    5. • Reporting
  2. • Module 2: Reconnaissance
    1. • Open-Source Intelligence (OSINT) 
    2. • Google hacking and alternative search engines
    3. • Subdomains and DNS enumeration
    4. • Public services enumeration
    5. • Discovering hidden secrets
  3. • Module 3: Introduction to Web Application testing
    1. • Modern Web standards and protocols
    2. • OWASP TOP 10
    3. • Role of web-proxy
    4. • Work automatization
    5. • Business and logic issues
    6. • Supply chain attacks and vulnerable components
    7. • Chaining security issues
    8. • SSL/TLS issues
    9. • Information disclosures
  4. • Module 4: Browser's security mechanisms
    1. • Introduction to Differences across implementations
    2. • Same Origin Policy
    3. • CORS and other exceptions
    4. • Security headers
    5. • Cookies and local storage security
    6. • Differences across implementations
  5. •  Module 5: Cross Site Scripting
    1. •  Reflected and Stored Cross Site Scripting
    2. •  Attacking Document Object Model
    3. •  DOM clobbering
    4. •  Bypassing weak CSP
  6. • Module 6: Injections
    1. •  Blacklisting vs whitelisting
    2. •  SQL injections
    3. •  Command injections
    4. •  Header splitting and injection
  7. • Module 7: Authentication and Authorization
    1. •  Attacks on authentication and authorization
    2. •  Attacks on sessions
    3. •  Insecure Direct Object Reference (IDOR) attacks
    4. •  Default credentials
    5. •  JSON Web Tokens
  8. • Module 8: Insecure file handling
    1. •  Path traversal
    2. •  Content manipulation
    3. •  Insecure file extensions
  9. • Module 9: Insecure inclusions
    1. • Local File Inclusion
    2. •  Remote File
  10. • Module 10: Testing API
    1. •  OWASP Top 10 for API
    2. •  Bypassing API access controls
    3. •  Mass assignment attack

After this course participants should be able to:

  • • Understand the most important aspects of web application penetration testing
  • • Discuss key aspects of penetration testing in terms of methodologies and legal aspects and reporting
  • • Look for vulnerabilities
  • • Exploit them in practice in CQURE’s custom-built training environment
  • • Use industry-standard tools such as the Kali Linux, Burp Suite, Bloodhound, Metasploit and the Wireshark
  • • Be prepared for a penetration test

Participants should have a solid understanding of cybersecurity concepts and the technical capacities to use Windows-based and Linux-based extensive labs.

An introductory course like Introduction to Penetration Testing (IPC) is highly recommended if you have no prior knowledge.

  • • Penetration tester 
  • • Security analyst 
  • • IT administrator 
  • • Cybersecurity professional
  • • "Geek" with IT background who wants to start an adventure in the cybersecurity pentesting field 

Kontakt oss: Kurs@sgpartner.no

Relaterte kurs