
notes link: https://drive.google.com/file/d/1FrDN1sBlknfZ0q9uqRsPohsUdXZubrby/view?usp=drive_link
Install and configure Kali Linux in a virtual machine using VMware or VirtualBox, download the official image, and set up the VM. Then update, upgrade, and optionally install GNOME.
Learn how directory traversal, also known as file path traversal, enables a web application to read arbitrary server files and potentially modify data through practical labs with burpsuite.
Explore a path traversal vulnerability in the display of product images and learn how using an absolute path reveals /etc/passwd in the lab.
Explore a lab illustrating a file path traversal vulnerability in image display, where the app strips certain characters, yet crafted dot-dot sequences bypass filters to access etc/password.
Explore content discovery and information disclosure vulnerabilities in web security. Learn how backups, configuration files, and admin portals can expose sensitive data and enable attacks through practical labs.
Explore information disclosure in error messages by triggering a lab on a Linux machine to reveal a vulnerable Apache Struts 2 third-party framework and its version.
Explore information disclosure on debugging page using Burp Suite to discover content, find CGI-bin php information file, obtain API key and secret keys, and submit the solution.
Explore how a stock check feature enables SSRF against an internal back-end. Brute-forcing the last octet (0-255) reaches the admin panel on port 8080 to delete Carlo.
Explore ssrf vulnerabilities and how a blacklist-based input filter can be bypassed to access admin panel. Learn lab techniques with burp suite to test the filter and simulate admin actions.
Explore remote code execution through a vulnerable image upload function, deploying a PHP web shell to exfiltrate the secret file from the home/carlos directory.
Bypass content-type restrictions in a vulnerable image upload to deploy a PHP web shell, exfiltrate data, and solve the lab using Winner and Peter, Burp.
Learn how obfuscation of file extensions enables uploading a web shell by bypassing server defenses, using double extensions and null byte tricks.
Explore the polyglot method to bypass image-based file upload checks and execute server-side code. Learn techniques such as content-type manipulation, double extensions, null bytes, and directory traversal.
Explore an unprotected admin panel with an unpredictable url by manually inspecting the application source code to locate it. Access the panel and delete the Carlos user to complete lab.
Learn to elevate from a normal user to admin by modifying a request parameter and a forgettable cookie to access the admin panel and delete a user.
Explore how to identify and exploit business logic vulnerabilities in a purchasing workflow by price tampering through request interception and Burp Suite, highlighting client-side controls risk.
Explore high level logic vulnerability in a purchasing workflow and learn how unvalidated inputs and cart manipulation can let an attacker set a custom price, using burp suite demonstrations.
Demonstrate insufficient workflow validation as a business logic vulnerability by manipulating the target via url and Burp Suite to bypass cart checks and payment verification in hands-on labs.
Welcome to the most complete Cybersecurity, Ethical Hacking & Penetration Testing course — packed with real-world techniques, tools, and hands-on labs!
Whether you're a total beginner or an aspiring pro, this all-in-one course will take you from the very foundations of IT and networking to advanced penetration testing, vulnerability exploitation, bug bounty hunting, and capture-the-flag (CTF) challenges.
In today’s world, cybercrime costs businesses trillions — and skilled ethical hackers are in high demand. This course gives you the practical knowledge and mindset of a hacker so you can legally secure systems before the bad guys do.
What You’ll Learn:
- Ethical hacking fundamentals & methodologies
- Kali Linux, Burp Suite, Nmap, Metasploit & Recon tools
- Exploit major web vulnerabilities (XSS, SQLi, SSRF, file upload, IDOR)
- Linux & Windows privilege escalation
- Information gathering, scanning, and reporting
- TryHackMe & CTFs walkthroughs (Mr. Robot, Vulnversity, HackPark, Skynet & more)
-Automation using Bash, Python & tools like Nuclei, Subfinder, Katana
-Real-world practice in offensive & defensive security
-Roadmap for certifications like CEH, OSCP, Security+, GPEN
Tools & Platforms You’ll Use:
Kali Linux, Parrot OS, Burp Suite (Pro & Community), OWASP ZAP
Nmap, Nikto, SQLMap, Hydra, John the Ripper, Hashcat
Metasploit Framework, LinPEAS, WinPEAS
Docker, VirtualBox, TryHackMe, Hack The Box, and more!
Who Is This Course For?
Complete beginners with no prior experience in cybersecurity
IT professionals and developers wanting to expand into ethical hacking
Students preparing for CEH, OSCP, or similar certifications
Bug bounty hunters and CTF enthusiasts
Freelancers and career changers looking to enter cybersecurity
What You’ll Build:
Your own virtual hacking lab using VirtualBox and Kali Linux
Automated recon tools and scanning scripts
Exploitation reports and documentation like a real pentester
Portfolio-ready CTF walkthroughs to show employers and clients
Why This Course?
This course is not just theory — it's designed to be deeply practical, engaging, and career-focused. You’ll learn the “how” and “why” behind every attack technique, with step-by-step demos, realistic scenarios, and exploit challenges you can practice immediately.
Are you ready to become a cybersecurity expert, ethical hacker, or professional pentester?