Course Name
Course Code : TKV65
Venue Details
Postal Code : 11001
Session Dates
Duration: 3 days (21 hours)
This course provides in-depth knowledge and hands-on practice in web application penetration testing using the OWASP Web Security Testing Guide (WSTG) and OWASP Top 10 standards. Participants will learn to identify, exploit, and mitigate common web vulnerabilities, conduct secure code reviews, and perform both manual and automated testing of modern web applications. The course emphasizes real-world scenarios to prepare participants for professional security assessments and compliance requirements.
Introduction to Web Application Security
Web threat landscape
OWASP Top 10 & WSTG overview
Attack surface of web applications
Testing Infrastructure and Setup
Lab setup with vulnerable apps (DVWA, Juice Shop, WebGoat)
Tools: Burp Suite, ZAP, SQLMap, wfuzz
Setting up intercepting proxies
Information Gathering & Reconnaissance
Fingerprinting technologies & frameworks
Directory/file enumeration
Identifying hidden parameters and endpoints
Testing Authentication & Session Management
Weak login implementations
Session fixation, session hijacking
Multi-factor authentication testing
Injection Flaws
SQL Injection, Command Injection, LDAP Injection
Tools and exploitation techniques
Cross-Site Scripting (XSS)
Reflected, stored, and DOM-based XSS
Payload crafting & bypass techniques
Broken Access Control
IDORs (Insecure Direct Object References)
Privilege escalation testing
Cross-Site Request Forgery (CSRF)
Exploitation of trust in authenticated users
Mitigation strategies
Security Misconfigurations
Common server and framework misconfigurations
Automated scanning with Nikto and Nmap
Testing Cryptography & Data Security
Insecure data storage
Weak TLS/SSL configurations
Improper cryptographic usage
Testing APIs & Modern Web Apps
REST & GraphQL API testing
JWT and token-based authentication flaws
Case study: API misconfiguration
Testing Business Logic Flaws
Logical bypass attacks
Abuse of workflows (e.g., coupon reuse, price manipulation)
Reporting & Remediation
Writing professional penetration testing reports
Mapping findings to OWASP WSTG & Top 10
Best practices for remediation
Hands-on Exercises
Summary and Conclusion
Mode of Delivery : The event can be attended both online and at nearby ProgNXT classroom by Individual Professionals and Corporate Employees as per the seat availability. Please Contact Us at [email protected] for checking the seat availability
Audience : We have a global audience that logs in to using their own computers to work hand in hand with our world-class instructors.
Assessment : Each training course will have ProgNXT Assessment at the end.
Certification : After successful passing of ProgNXT Assessment, ProgNXT Certification will be provided, which has got acceptance in 55+ Countries.
| Global Region | Location | Start Date | End Date | Action |
|---|---|---|---|---|
| | | | | |
| | | | | |
| | | | | |
| | | | | |
| | | | | |