
notes link: https://drive.google.com/file/d/1FrDN1sBlknfZ0q9uqRsPohsUdXZubrby/view?usp=drive_link
Install and configure Kali Linux in a virtual machine using VMware or VirtualBox, download the official image, and set up the VM. Then update, upgrade, and optionally install GNOME.
Master Kali Linux from basic to advanced by mastering the command line, file management, and root versus user navigation. Learn commands like cp, mv, rm, chmod, nano, leafpad, wget.
Configure and install Burp Suite on Windows, install Java and JDK, and explore the Community version features—proxy, intruder, and repeater—with a focus on manual vulnerability assessment.
Learn to master burp suite professional by configuring settings, building in-scope targets, crawling and auditing for vulnerabilities, using proxy, repeater, intruder, and generating HTML reports.
Learn how directory traversal, also known as file path traversal, enables a web application to read arbitrary server files and potentially modify data through practical labs with burpsuite.
Explore a path traversal vulnerability in the display of product images and learn how using an absolute path reveals /etc/passwd in the lab.
Explore a lab illustrating a file path traversal vulnerability in image display, where the app strips certain characters, yet crafted dot-dot sequences bypass filters to access etc/password.
Automate path traversal vulnerability testing with a comprehensive payload list for Windows and Linux, using Burp suite intruder to brute force and identify 200 status responses revealing sensitive files.
Explore content discovery and information disclosure vulnerabilities in web security. Learn how backups, configuration files, and admin portals can expose sensitive data and enable attacks through practical labs.
Explore information disclosure in error messages by triggering a lab on a Linux machine to reveal a vulnerable Apache Struts 2 third-party framework and its version.
Explore information disclosure on debugging page using Burp Suite to discover content, find CGI-bin php information file, obtain API key and secret keys, and submit the solution.
Automate discovering information disclosure vulnerabilities using Dear Buster, Content Discoverer, and Fuff with a GUI, targets, and wordlists for faster web app pentesting.
Exploit an OS command injection vulnerability in the lab by intercepting a stock check request, injecting commands with pipes to reveal the current user via whoami.
Explore how a stock check feature enables SSRF against an internal back-end. Brute-forcing the last octet (0-255) reaches the admin panel on port 8080 to delete Carlo.
Explore ssrf vulnerabilities and how a blacklist-based input filter can be bypassed to access admin panel. Learn lab techniques with burp suite to test the filter and simulate admin actions.
Learn how file upload features can become attack vectors when servers fail to validate file name, type, content, and size, potentially enabling web shells and remote code execution.
Explore remote code execution through a vulnerable image upload function, deploying a PHP web shell to exfiltrate the secret file from the home/carlos directory.
Bypass content-type restrictions in a vulnerable image upload to deploy a PHP web shell, exfiltrate data, and solve the lab using Winner and Peter, Burp.
Learn how obfuscation of file extensions enables uploading a web shell by bypassing server defenses, using double extensions and null byte tricks.
Explore the polyglot method to bypass image-based file upload checks and execute server-side code. Learn techniques such as content-type manipulation, double extensions, null bytes, and directory traversal.
Explore access control vulnerabilities and privilege escalation in web apps, covering authorization, session management, insecure direct object references, acls, and authentication bypass.
Explore an unprotected admin panel with an unpredictable url by manually inspecting the application source code to locate it. Access the panel and delete the Carlos user to complete lab.
Learn to elevate from a normal user to admin by modifying a request parameter and a forgettable cookie to access the admin panel and delete a user.
Investigate access control vulnerabilities in a lab that shows how a user can modify their role in the user profile to access an admin panel, illustrating vertical privilege escalation.
Demonstrates how a user id controlled by a request parameter with password disclosure enables privilege escalation by retrieving administrator password and deleting the Carlos account, introducing insecure direct object reference.
Explore insecure direct object references and access control flaws, and learn how horizontal privilege escalation can expose server-stored data like chat logs and passwords in a hands-on lab.
Explore business logic vulnerabilities in web apps, including price tampering, locking and holding, coupon abuse, data validation flaws, and forging requests, while assessing integrity and availability.
Explore how to identify and exploit business logic vulnerabilities in a purchasing workflow by price tampering through request interception and Burp Suite, highlighting client-side controls risk.
Explore high level logic vulnerability in a purchasing workflow and learn how unvalidated inputs and cart manipulation can let an attacker set a custom price, using burp suite demonstrations.
Explore a business logic vulnerability that enables vertical privilege escalation to gain admin privileges, access the admin panel by changing the email, and delete a user.
Explore business logic vulnerabilities that permit changing a password without validating the current password, escalate to an admin account, and use Burp to intercept and modify requests.
Demonstrate insufficient workflow validation as a business logic vulnerability by manipulating the target via url and Burp Suite to bypass cart checks and payment verification in hands-on labs.
Welcome to the most complete Cybersecurity, Ethical Hacking & Penetration Testing course — packed with real-world techniques, tools, and hands-on labs!
Whether you're a total beginner or an aspiring pro, this all-in-one course will take you from the very foundations of IT and networking to advanced penetration testing, vulnerability exploitation, bug bounty hunting, and capture-the-flag (CTF) challenges.
In today’s world, cybercrime costs businesses trillions — and skilled ethical hackers are in high demand. This course gives you the practical knowledge and mindset of a hacker so you can legally secure systems before the bad guys do.
What You’ll Learn:
- Ethical hacking fundamentals & methodologies
- Kali Linux, Burp Suite, Nmap, Metasploit & Recon tools
- Exploit major web vulnerabilities (XSS, SQLi, SSRF, file upload, IDOR)
- Linux & Windows privilege escalation
- Information gathering, scanning, and reporting
- TryHackMe & CTFs walkthroughs (Mr. Robot, Vulnversity, HackPark, Skynet & more)
-Automation using Bash, Python & tools like Nuclei, Subfinder, Katana
-Real-world practice in offensive & defensive security
-Roadmap for certifications like CEH, OSCP, Security+, GPEN
Tools & Platforms You’ll Use:
Kali Linux, Parrot OS, Burp Suite (Pro & Community), OWASP ZAP
Nmap, Nikto, SQLMap, Hydra, John the Ripper, Hashcat
Metasploit Framework, LinPEAS, WinPEAS
Docker, VirtualBox, TryHackMe, Hack The Box, and more!
Who Is This Course For?
Complete beginners with no prior experience in cybersecurity
IT professionals and developers wanting to expand into ethical hacking
Students preparing for CEH, OSCP, or similar certifications
Bug bounty hunters and CTF enthusiasts
Freelancers and career changers looking to enter cybersecurity
What You’ll Build:
Your own virtual hacking lab using VirtualBox and Kali Linux
Automated recon tools and scanning scripts
Exploitation reports and documentation like a real pentester
Portfolio-ready CTF walkthroughs to show employers and clients
Why This Course?
This course is not just theory — it's designed to be deeply practical, engaging, and career-focused. You’ll learn the “how” and “why” behind every attack technique, with step-by-step demos, realistic scenarios, and exploit challenges you can practice immediately.
Are you ready to become a cybersecurity expert, ethical hacker, or professional pentester?