Web Penetration Testing

$ 1.000

In this course, we will look at all the vulnerabilities associated with web applications and proprietary web services. These vulnerabilities will be tested in black box and white box. In Black Box mode, special Web Fuzzing and Web Crawling techniques can be used. The process of preparing laboratory environments to detect vulnerabilities will also be in the form of a White Box, which can lead to the emergence of critical-level vulnerabilities and the chain of Remote Code Execution attacks.

View full Syllabus




Organization Name: Web Penetration Testing | 10/07/2026
Seats:
Total: $ 0 Discounted price
Courses in this Organization

Category: Offensive Security

Hardware Requirements:

Safe Exam Browser

  • Windows 10, 11
  • macOS

Windows

  • Windows 10 and 11 are preferred.
  • Windows 7 and 8.1 will also work.
  • Dual-core processor (2+ GHz)
  • 4+ GB RAM.
  • Chrome, Firefox, or Microsoft Edge will also work.

Macintosh

  • OS X El Capitan
  • 1.2 GHz Intel Core M dual-core processor.
  • 4+ GB RAM.
  • Chrome, Firefox, or Safari will also work.

Linux

  • Ubuntu +16 – Kali Linux +2020
  • 1.2 GHz Intel Core M dual-core processor.
  • 4+ GB RAM.
  • Chrome, Firefox, or Safari browsers will also work.
Course LevelAdvanced, Beginner, Intermediate
Access TimeUnlimited
How to AccessOnline

Reviews

There are no reviews yet.

Only logged in customers who have purchased this product may leave a review.

Hands-on Labs

Awarding a Valid Certificate

Unlimited Access

Course Syllabus

Introduction

  1. Hypertext Transfer Protocol
  2. Methodologies
  3. Burpsuite Pro
  1. Content Management System
  2. MS Exchange
  3. Web Access Outlook
  4. Web Architectures
  5. Web App Technologies
  6. Languages and Frameworks
  7. Web Design Patterns
  8. Browser Extensions
  9. Data Formats
  10. REST and SOAP
  11. Java and Struts
  12. Encoding Schemes

Information Gathering

  1. Search Engine Discovery
  2. Fingerprint Web Server
  3. Review Webserver Metafiles
  4. Enumerate Applications
  5. Review Webpage Content
  6. Identify Application Entry Points
  7. Map Execution Paths
  8. Fingerprint Web Application Framework
  9. Map Application Architecture
  1. Infrastructure
  2. People Investigation

Web Vulnerabilities

  1. Network Configuration
  2. App Platform Configuration
  3. File Extensions Handling
  4. Review Old Backup
  5. Enumerate Admin Interfaces
  6. HTTP Methods
  7. HTTP Strict Transport Security
  8. RIA Cross Domain Policy
  9. File Permission
  10. Subdomain Takeover
  11. Cloud Storage
  12. Content Security Policy
  13. Path Confusion
  1. Role Definitions
  2. User Registration
  3. Account Provisioning
  4. Account Enumeration
  5. Weak Username Policy
  1. Credentials Encrypted Channel
  2. Default Credentials
  3. Weak Lock Out Mechanism
  4. Bypassing Authentication Schema
  5. Vulnerable Remember Password
  6. Browser Cache Weaknesses
  7. Weak Password Policy
  8. Weak Security Question Answer
  9. Weak Password Reset Functionalities
  10. Weaker Authentication in Alternative Channel
  11. Multi-Factor Authentication
  1. Directory Traversal File Include
  2. Bypassing Authorization Schema
  3. Privilege Escalation
  4. Insecure Direct Object References
  5. OAuth Weaknesses
  1. Session Management Schema
  2. Cookies Attributes
  3. Session Fixation
  4. Exposed Session Variables
  5. Cross Site Request Forgery
  6. Logout Functionality
  7. Session Timeout
  8. Session Puzzling
  9. Session Hijacking
  10. JSON Web Tokens
  1. Reflected Cross Site Scripting
  2. Stored Cross Site Scripting
  3. HTTP Verb Tampering
  4. HTTP Parameter Pollution
  5. SQL Injection
  6. LDAP Injection
  7. XML Injection
  8. SSI Injection
  9. XPath Injection
  10. IMAP/SMTP Injection
  11. Code Injection
  12. Command Injection
  13. Insecure Deserialization
  14. HTTP Splitting Smuggling
  15. Host Header Injection
  16. Web Cache Poisoning
  17. Server Side Template Injection
  18. Server Side Request Forgery
  19. Mass Assignment
  20. Regular Expression DoS
  1. Improper Error Handling
  1. Weak Transport Layer Security
  2. Padding Oracle Attack
  3. Information Unencrypted Channel
  4. Weak Encryption
  1. Logic Data Validation
  2. Ability to Forge Requests
  3. Integrity Checks
  4. Process Timing
  5. Race Conditions
  6. Circumvention of Work Flows
  7. Defenses Against Application Misuse
  8. Upload of Unexpected File Types
  9. Upload of Malicious Files
  10. Payment Functionality
  1. DOM-Based Cross Site Scripting
  2. JavaScript Execution
  3. HTML Injection
  4. Client Side URL Redirect
  5. CSS Injection
  6. Client Side Resource Manipulation
  7. Cross Origin Resource Sharing
  8. Client Side Template Injection
  9. Cross Site Flashing
  10. Clickjacking
  11. WebSockets
  12. Web Messaging
  13. Browser Storage
  14. Cross Site Script Inclusion
  15. Reverse Tabnabbing
  1. Broken Object Level Authorization
  2. Broken Authentication
  3. Excessive Data Exposure
  4. Lack of Resources and Rate Limiting
  5. Broken Function Level Authorization
  6. Mass Assignment
  7. Security Misconfiguration
  8. Injection Attack
  9. Improper Assets Management
  10. Insufficient Logging and Monitoring

Course Quality

  • In cybersecurity training courses, all dimensions and aspects of a subject are not always addressed, and this issue causes the operational capacity of students to decrease significantly, but in this course, all issues have been addressed:
  1. The cause of the vulnerability event
  2. How to detect vulnerability as a black box
  3. How to discover vulnerability as a white box
  4. How to obfuscate and bypass defense mechanisms
  5. How to exploit and design the exploitation chain

Several courses are offered in one course

Web Penetration Testing (Beginner)20%

20%

Web Penetration Testing (Advanced)40%

40%

Web Penetration Testing (Bug Bounty)60%

60%

Web Penetration Testing (Red Team)80%

80%

Web Penetration Testing (Full)100%

100%

Learning Management System

  • The online education management system will have the task of intelligent and browser-based guidance of users, as well as the establishment of theoretical and practical tests.
  • Another task of this system will be to record the duration of courses and completion of course topics, so that it can finally display accurate statistical information to the companies applying for human resources and the users themselves.
  • In this system, there are two contents of the course, the first is the educational videos of each lesson and their topics, the second is an online booklet, which is presented on the page of each lesson and all the points of that topic, and users can read them in the LMS system.
  • It should be noted that the videos and texts of the training course are only available through the LMS system and cannot be downloaded or copied, of course, course users will always have access to the training system for a lifetime.

Hands-on Labs

  • Another feature of this course is to have online Hands-on Labs that are designed for each of the Syllabus topics, at least three to five different scenarios and with the approach of the real event environment of that topic.
  • Access to each of the lab sections is such that any lesson that is opened to users according to the LMS educational path, will be available to users according to that lesson’s online laboratory section, and as long as the user has operational challenges If you don’t do it, the next lesson won’t open.
  • The duration of access to each part of the online laboratory is unlimited, of course, until the user passes the practical challenge. If the challenge is passed, that challenge will be removed from the user’s reach and the next challenges will be opened.
  • An information counter has been placed in the online laboratory to track all the events and academic trends of the users and show them to the users themselves, this information will also be used in order to rank the users.

Theory and Practical Exam

  • Each lesson has a four-choice theory test that is based on the material taught, and the student must pass this test by taking this test and scoring more than 70.
  • After taking the theory test and scoring more than 70, the student can proceed to the practical test and solve the test challenge in the practical laboratory.
  • If both the theoretical and scientific challenges are passed, the next lesson of the course will be opened. Otherwise, the lesson will not be opened.
  • At the end of the course, a completely realistic theory and practical test with CTF standards has also been designed, and whatever score the student receives in this final test, that score will be recorded in the course certificate.

Tools Installer

  • In the training courses of the Unk9vvN research team, users are given two installer tools that prepare their Linux and Windows operating systems to be used in order to perform operational commands in the real world.
  • The first installer is for basic Linux operating systems such as Ubuntu and Kali Linux and the second installer is for basic Windows operating systems such as Windows 11 and Windows Server.
  • These installation tools speed up the preparation process of the operational laboratory and can easily prepare the operating system environment from the required tools of the course.

Cheat Sheet and Checklist

  • For each training course, a cheat sheet is provided, which is designed as a complete, dedicated manual and is provided to users, this manual is aimed at facilitating the implementation of test operations that users should use in the operational part, these manuals It will include the introduction of quality tools and how to use them for all kinds of tests.
  • In addition to the cheat sheet, a comprehensive and complete checklist is provided so that users, after learning the lessons presented in the course, based on that checklist and cheat sheet, can perform security assessments and specifically discover weak and vulnerable points.

Association with Teachers

  • Course users can be in direct contact with professors on two communication platforms, the first is the Discord program for weekly voice question and answer sessions, the second is the Telegram program and a semi-private group for raising questions and specialized discussions with professors and course designers.
  • The training courses of the Anon research team are not based on one person and are designed by a team, therefore, in relation to any technical problems or questions, users can communicate with the designers and professors of the course on the mentioned platforms on a daily basis. And raise their issues.

Domestic and Foreign Jobs

  • Offensive security specialties, especially penetration testing, are always offered alongside defensive security services, and experts in this field can provide great help to a professional cybersecurity solution. Therefore, penetration testing jobs are always needed both inside Iran and outside Iran, and they offer appropriate salaries.
  • To check penetration testing jobs in Iran, you can refer to jobvision.ir and jobinja.ir, and also for jobs in this field outside of Iran, you can refer to infosec-jobs.com and indeed.com websites. Evaluate the careers of this field.

FAQ

  1. Basics of Network
  2. Basics of Linux
  3. Basics of HTML and CSS
  4. Basics of JavaScript and Node.js
  5. Basics of JSON and XML
  6. Basics of SQL and NoSQL
  7. Basics of PHP
  8. Basics of Java
  9. Basics of C-Sharp
  10. Basics of ASP.NET
  11. Professional Python
  • Red team members
  • Vulnerability assessment experts
  • Penetration testers
  • Security consultants
  • Developers
  • IT managers
  • System Architects
  • Software students
  • You can perform an in-depth analysis of the open source code of web applications without compilation.
  • Identify logical vulnerabilities that many enterprise scanners fail to detect.
  • Participating in bug bounty programs and discovering Critical level vulnerabilities.
  • Providing web penetration testing services at the organizational and public level.

Similar Courses