
Show sqlmap usage to identify a vulnerability, enumerate the MySQL database, and dump a credit card table's columns such as key id, key number, CVV, and expiration.
Explains what a virtual machine is, how it imitates hardware, and how VirtualBox enables running Kali Linux with isolated guests.
Install Kali Linux 2020 via VirtualBox by importing the VM image. Start the VM and log in with the default credentials Carly after adjusting the hardware settings.
Install the Oracle VM VirtualBox extension pack from virtualbox.org/wiki/downloads, then boot Kali Linux in VirtualBox; the first boot takes a few minutes and prompts for the username and the password.
Log in to Kali Linux 2020.2 in VirtualBox with the default username Kali and password Kali, then run sudo apt update and sudo apt upgrade to understand update vs upgrade.
Set Kali Linux to full screen in VirtualBox. Explore the filesystem hierarchy standard (FHS) and top-level directories such as bin, boot, dev, home, and media.
Explore how the who am i command reveals the current user in Linux and Windows, using Kali as an example, and note switching to root with su.
Master switching to the root with su and sudo, understand root privileges and authentication, and learn pwd for the current directory.
Explore essential Linux commands: use cat to view and concatenate files, copy with cp, create directories with mkdir, and navigate with cd to manage files and folders.
Use mv to move and rename files or directories, silently, with source and destination, and use rm to remove files or folders, employing -r or -f for directories.
Explore essential linux system and user commands, from present working directory to forensics related queries, covering uptime, dmesg, df, fdisk, free, who, w, history, last, and finger.
Explore essential network commands like ping, whois, dig, ifconfig, netstat, and arp to test connectivity, query DNS data, view interfaces, and manage ARP caches.
Create a new user with sudo permissions in Kali Linux, set a password, and join the sudo group using usermod, then set the login shell to /bin/bash and verify access.
Switch from root to a standard user, verify user and group entries, remove the user from the pseudo group, and delete the user via the command line.
Update and upgrade Kali Linux using sudo apt update and apt upgrade (with -y and dist-upgrade) to ensure you run the latest software before downloading and installing Xampp.
Master XAMPP theory and installation to set up a local testing environment with Apache, MySQL, PHP, and Perl. Learn how this cross-platform open-source package enables testing web projects before deployment.
Explore command injection at a high security level, showing how a blacklist can be bypassed using a pipe without space to execute arbitrary commands and reveal information.
The lecture demonstrates local file inclusion using directory traversal to access sensitive files like password file, compares LFI with remote inclusion, and notes lack of input validation under low security.
Explore high security file inclusion (local file inclusion, lfi) with strict input validation and exact path usage on dvwa, including php info access under permission-aware live-site testing.
Examine the file upload vulnerability in low-security web apps and how attackers upload files to execute code. DVWA allows image uploads and checks jpg, jpeg, png extensions.
Explore medium level file upload vulnerabilities, bypass input validation with content-type manipulation, and use Burp Suite and proxy settings to intercept and upload a PHP file.
This lecture demonstrates xss dom testing across dvwa security levels, showing how to bypass low, medium, and high protections with hash inputs, alerts, document.cookie, and language whitelisting.
Explore stored cross-site scripting (XSS) vulnerabilities, including second order or persistent XSS, and see how poor input validation enables JavaScript payloads, alert boxes, and cookie access at a low security level.
Explore a medium level stored XSS vulnerability by bypassing input validation in a guest book, extending field length, and extracting document.cookie to reveal session data.
Explore xss stored at high level security and test low and medium levels. View source reveals sanitized inputs while script and tag attempts test dom-based stored and reflected xss.
Install and run Mutillidae II on Kali Linux using LAMP, clone from GitHub, and launch Apache and MySQL for a local vulnerable web lab with 40 OWASP top ten vulnerabilities.
fix root access denied by skipping grant-tables and restarting the services, then refresh the localhost to confirm the warning is resolved.
Explore sql injection in a practical session using zamp and localhost, referencing OWASP top ten, revealing data from accounts by manipulating sql queries like or 1=1 and dash dash comments.
Explore sql injection on a vulnerable web page using Mutillidae, 1=1 techniques, and comment-based query termination to extract user info and view account details.
Discover how sqlmap automates detection and exploitation of sql injection flaws across databases such as MySQL, SQL Server, and Oracle, with Burp Suite workflow.
Explore SQL injection testing with SQL map, from capturing requests and banner checks to database enumeration in MySQL Mutillidae and dumping credit card data.
Learn to scan a web server with Nikto on EC2, a web application vulnerability scanner that checks for dangerous files, outdated server versions, and misconfigurations via host-based scans on Mutillidae.
Demonstrate cross-site scripting in Mutillidae, showing how unsanitized user input is reflected into web pages to execute client-side scripts and access cookies, with DNS lookup examples.
Demonstrates dom-based XSS when input is injected via inner HTML, executing scripts and defacing the page, unlike inner text which renders data safely.
Explore stored XSS, a persistent payload stored in a database that can execute in every viewer's browser and deface pages due to missing input validation and output encoding.
Explore the browser exploitation framework (BeEF) to hook browsers via JavaScript, demonstrate cross-site scripting risks, and manage infected clients through a web UI on Kali.
Demonstrate reflected xss using the beef framework to inject hook.js into a target browser, log in with beef / 1,2,3, and explore offline and online browsers in Mutillidae.
Explore how the beef framework gains control of a victim page by reflecting input and loading hook.js. See browser modules for alerts, redirects, and credential harvesting via fake login pages.
Discover owasp juice shop, a modern insecure web app with top ten vulnerabilities, built in node.js, express, and angular. Install nodejs and npm on kali to prepare environment before cloning.
Clone the juice shop project from the provided link, then run npm install to install dependencies. If audits reveal vulnerabilities, run npm audit fix to address them.
Learn to fix juice shop installation issues with npm install --unsafe-perm, start the server on port 3000, and view the OWASP juice shop web app demonstrating vulnerabilities.
Explore how to locate the Juice Shop scoreboard by inspecting main.js and client-side code, uncovering level one challenges and hidden URLs in this ethical hacking course.
Navigate a level 1 sensitive data exposure challenge by intercepting requests, discovering a confidential document via file listings, and extracting acquisition.md to reveal confidential data.
Explore a level 1 dom-based xss challenge by injecting an iframe payload into the search input to trigger a JavaScript alert, using the browser inspector to verify the attack.
Identify the error handling vulnerability in the level one challenge, illustrating how insecure handling of errors and unexpected paths causes internal server errors and security misconfiguration.
Explore the bonus dom xss level 1 challenge in the owasp juice shop, applying the provided javascript payload to reproduce a dom based xss attack and review the reading material.
Explore the exposed metrics endpoint in the Owasp juice shop level 1 challenge, uncovering cross-domain data exposure via an API endpoint used by a popular monitoring system (Prometheus).
examine the outdated white list in the unvalidated redirect category of the juice shop, using dev tools to locate a crypto redirect endpoint toward blockchain.info.
Explore a level one miscellaneous challenge by reading the privacy policy in the OWASP Juice Shop, then log in with a working email to access and read the policy.
Identify and exploit repetitive registration vulnerabilities by mismatching the repeat password field in the user registration form, illustrating improper input validation and the dry principle.
Hello everyone..!!
welcome to the CWAPT i.e. the Complete Web application Penetration Testing Practical Course . My name is DEBAYAN DEY and i will be your Instructor for the CWAPT Course.
Now this course is designed for anyone who is interested in learning how an attacker attack and get the information from website by exploiting various vulnerabilities available.
CWAPT is designed by keeping in mind that most of us are having laptops or computer machine to work for most of the time and in a survey , we came up with the answer that most of the Computer users are very much interested in Learning how Web Application Penetration Testing works and what are the process in which we use penetration testing and security skills to find different vulnerabilities in web applications. As we all know , website and webservers plays an important role in every modern organization, Thats why in this course curriculum , Only you need a computer device and this entire course is 100% practical based ! isn't this amazing ??? and everything will be explained in depth , followed with reading materials and quizes which will give you a boost in the field of Ethical Hacking!!! so all in one , you just require a computer device and turn it into powerful ethical hacking machine.
Little brief about my name , i am Certified Secure Computer User (CSCU) v2 , and Certified Ethical Hacker (CEH V10) from EC COUNCIL
also i am certified Google IT support from Google , and currently doing micromaster in the Field of Cyber Security from Rochester institute of technology (RIT) New York in edx .
here are few of my other accomplishments in the field of cyber security ,
Introduction to Cyber Attacks , New York University
introduction to Cyber security for business , University of Colorado System
Palo Alto Networks academy cybersecurity foundation , Palo alto networks
International cyber conflicts , The State University of New York
Cyber Attacks Countermeasures , New York University
Networking ans security Architecture with Vmware NSX
Enterprise System Management and security ,University of Colorado System
Rest we'll have a meet and greet section to know other Learners ...!!!
so whats there in this CWAP COURSE?
First of all i would love to tell you , that this course is not limited to time . you may see 4 or 5 sections today , once you land in this course after few weeks , you'll see more sections and videos are added up. so this is the advantage of taking this course that you'll get regular updates about the new features and attacks and how you , as an individual person as well as organization or company can prevent from such an attack.
The web application penetration testing key outcome is to identify security weakness across the entire web application and its components (source code, database, back-end network).It also helps in prioritizing the identified vulnerabilities and threats, and possible ways to mitigate them.
so keeping these outcomes in mind , in 1st section of CWAPT course ,
you'll come across the setting up the lab environment wherein you'll download N install virtual box , then Kali linux 2020 and the entire configuration.
Meet and Greet !!!
Downloading and installation of virtual box
Understanding of what is Virtual Machine
Download of Kali Linux Virtual Box image
Installation of Kali linux 2020
Booting up kali in virtual box for the 1st time
Default login and update and upgrade
Full Screen and understanding FSH i.e. File System Hierarchy
and much more with Reading Materials and Quizzes ..!!
in 2nd section ,
we will come across various commands used in Kali Linux and we'll get familiar with our Hacking machine. this section is very important as you'll be understanding the basic commands which we will be using in our course , so make sure you understand this section very clearly.
Basic linux command who am i
Basic Commands su and pwd
Basic command ls touch nano
Basic command cat cp mkdir
Basic Command mv and rm
System and User Commands
Network commands
Add New User with full sudo Permission
How to delete user using command line
and much more with Reading Materials and Quizzes ..!!
next section , i.e. our 3rd Section will cover DVWA.
What is DVWA?
DVWA is a DAMM VULNERABLE WEB APP coded in PHP/MYSQL. Seriously it is too vulnerable. In this app security professionals, ethical hackers test their skills and run this tools in a legal environment. It also helps web developer better understand the processes of securing web applications and teacher/students to teach/learn web application security in a safe environment.
What is DVWA
XAMPP Theory and Installation
DVWA download Install and configuration with XAMPP
Command Injection Low , Medium and High Security
File Inclusion Low , Medium and High Security
File Upload Low , Medium and High Security
XSS DOM Low , Medium and High Security
XSS Reflected Low , Medium and High Security
XSS Stored Low , Medium and High Security
and much more with Reading Materials and Quizzes ..!!
The aim of DVWA is to practice some of the most common web vulnerability, with various difficulties levels.
We gonna learn what is DVWA used for , we'll use XAMP and understand its working.
As the name suggests DVWA has many web vulnerabilities. Every vulnerability has four different security levels, low, medium, high and impossible. The security levels give a challenge to the ‘attacker’ and also shows how each vulnerability can be counter measured by secure coding.
We'll cover command injection , file inclusion , file upload various cross site scripts, we will come across burp suite and much more
So every month , you'll get regular updates in this DVWA section.
Coming to our 4th section , we will work with OWASP MUTILLIDAE.
OWASP Mutillidae II is a free, open source, deliberately vulnerable web-application providing a target for web-security enthusiast. it Has over 40 vulnerabilities and challenges. Contains at least one vulnerability for each of the OWASP Top Ten 2007, 2010, 2013 and 2017.
Download and install Mutillidae II
Root access denied fixed
SQL Injection
SQL Injection Reexplained
SQL injection with SQL MAP
How to solve show hints in security level 5 challenge
How to scan a webserver using NIKTO
XSS in Mutilidae Theory and Practical
DOM based XSS Explanation
Reflected XSS
Stored XSS
BEEF Framework
and much more with Reading Materials and Quizzes ..!!
So from a variety of 40 vulnerabilities , 1st we gonna cover , sql injection , sql map, how to solve security level challenges , we'll learn how to scan webservers using Nikto , various XSS attacks , MORE Importantly , we will learn the usage of burp suite , and neef Framework , which is very essential to understand and learn from Website Penetration tester perspective and wr have much more to cover in this section as well .
So every month , you'll get regular updates in this Mutillidae section as well.
Coming to our next section , i.e. 5th Section , we have OWASP JUICE shop.
OWASP Juice Shop is probably the most modern and sophisticated insecure web application! It can be used in security trainings, awareness demos, Ctfs etc.
What is OWASP Juice shop and installation of nodejs and npm
OWASP juice shop up in running
Finding the Score Board Level 1 Difficulty Challenge
Zero Star Feedback Level 1 Difficulty Challenge
Access Confidential Document Level 1 Difficulty Challenge
DOM based XSS Level 1 Difficulty Challenge
Error Handling Level 1 Difficulty Challenge
Missing Encoding Level 1 Difficulty Challenge
Bonus Payload DOM XSS Level 1 Difficulty Challenge
Exposed Metrics Level 1 Challenge
Outdated WhiteList Level 1 Challenge
Privacy Policy Level 1 Difficulty Challenge
Repetitive Registration Level 1 Difficulty Challenge
and much more to cover ...!!!
Juice Shop encompasses vulnerabilities from the entire OWASP Top Ten along with many other security flaws found in real-world applications!
Currently we are having 6 levels in owasp juice shop . we will start with level 1 and gradually increase our difficult level.
We gonna cover , missing encoding , error handling security , confidential document , hoe to extract sensitive data , we'll see how we can invade privacy policy , weird cryptographic issues and much more.
So every month , you'll get regular updates in Owasp Juice Shop section as well.
So , by going through all these sections , you'll be comfortable enough to understand how Web Application Penetration Testing works and with regular updates , you'll be able to brush up your skills as well.
Plus you'll have a bonus section as well which will guide you through various upcoming courses as well my Instagram page and youtube channel where you'll get regular updates in the field of cyber security and travel and tourism across the globe.
So all the sections will cover Quizzes , Assignments and Reading Materials .
Also , all the sections will be updated on regular basis and new sections will also be added up , so once you are enrolled in the course , you'll surely gonna learn various techniques how attackers attack and how we can safe ourselves from getting attacked.
Most importantly , this course is completely for educational purpose
all the attacks which an attacker perform are demonstrated to you so that you understand the technology and the art behind it and you're not fooled by any kind of social engineering.
This course is for educational and awareness purpose , to make everyone aware and be safe and protect your data.
Its a request , please do not perform any illegal activities , Udemy and me ( Debayan Dey ) is not responsible for your illegal activities you perform.
Feel Free to Reach out at any point of time , i will be happy to Help you , and if you face any PROBLEM , just post your DOUBTS , you will be Answered within 24hrs to 48hrs of time ..!!!!!
so, welcome to the world of Complete Web application Penetration Testing Practical Course .
ARE YOU EXCITED to learn 100% complete practical course and help your family , Organization and Company stay secured and safe from data theft and from hackers ?
wish you all the best !!!
Do follow our Instagram page and youtube channel for regular updates .
Wish you all the best...!!!!
See you in the course landing page ....!!!!