
Learn OWASP-based security testing for web apps, APIs, Android, and source code with demos using Burp Suite, Nmap, Zed Attack Proxy, and other tools.
Explore API fundamentals, producer and consumer roles, and a three-tier client–server model. Learn data transfer formats like JSON, XML, and YAML and how HTTP, HTTPS, TLS shape security testing.
Explore the fundamentals of client–server API security, including HTTP vs HTTPS, TLS versions, and request/response headers, and learn to test HTTP methods and status codes.
Pls find the material using below link
Explore the three-tier architecture—front end, back end, and database—and how each layer validates requests, with a focus on security testing and API types such as REST, SOAP, and GraphQL.
Master api syntax and security testing basics, including http methods, base uri, endpoints, query parameters, payloads, headers, and authorization. Study threats, vulnerabilities, cvss, cve, vat, and penetration testing.
Discover how to identify excessive sensitive data exposure and insecure design per OWASP guidelines, and practice tech-stack discovery with Wappalyzer, WhatRuns, and BuiltWith on web apps and APIs.
Identify insecure design by detecting open network ports and the services they expose, mapping port numbers to protocols such as http, https, ftp, smtp, imap, pop3, and sql. Use shodan and nmap/zenmap to scan targets, interpret open, filtered, or unnecessary ports, and collaborate with developers to close nonessential services for secure deployment.
Identify open ports and practice network mapping with Nmap, Shodan, and Zenmap, saving reports and guiding banking domain developers on port management.
IMPORTANT NOTE
Please Note: This course is pulled out from live sessions. So, you will hear student interactions as well. We recommend watching the free preview videos to ensure the teaching style and content meet your expectations before investing your time and money.
COURSE DESCRIPTION
This course offers an in-depth, hands-on journey into the world of Web Application and API Security Testing, combining foundational concepts with practical exercises using real-world vulnerable applications and industry-standard tools. From understanding the fundamentals of web architecture and HTTP protocols to exploring OWASP Top 10 vulnerabilities, the curriculum provides a comprehensive roadmap for mastering both Web and API security.
Learners will be introduced to various types of APIs including REST and SOAP, along with critical security testing techniques using tools like Burp Suite, Vooki, Yazhini, Nmap/Zenmap, and Snyk. You'll learn how to simulate attacks, identify vulnerabilities, and understand how enterprise applications function across front-end, back-end, and database layers.
Additionally, the course includes the setup and exploitation of popular intentionally vulnerable applications like OWASP Juice Shop, Web Goat, and more. With a strong focus on hands-on experience, the course also covers Android APK security testing and scanning open-source code for vulnerabilities.
Whether you're a beginner or a security enthusiast, this course will help you gain confidence in understanding, identifying, and mitigating security flaws in modern web applications and APIs.