
Master the OWASP top ten with hands-on demos on Juice Shop, from environment setup to practical fixes for broken access control, cryptographic failures, injection, and more.
Install the OWASP juice shop locally by meeting system requirements, installing Node.js on Windows, verifying with node -v, and preparing to git clone in the next step.
Clone the juice shop repo with depth 1, install dependencies with npm install, start the server, and access it on localhost:3000 to learn the OWASP top ten hands-on.
Install burp suite community edition on a Windows 64-bit system, run the installer with default settings, and start a temporary project; prepare to intercept browser traffic in the next lecture.
Configure Burp Suite as a proxy in Chrome using Foxy Proxy, setting the ip address and port, and install the Burp certificate to authorize traffic.
Explore broken access control in the OWASP top ten with a hands-on Juice Shop demo, identifying vulnerabilities and learning remediation steps.
Explain cryptographic failures as OWASP's second top vulnerability, illustrate risks from clear-text data and weak algorithms, and outline practical prevention with encryption, secure keys, TLS, and HTTP Strict Transport Security.
Explore injection vulnerabilities, including SQL injection and cross-site scripting, and learn practical remediation with parameterized queries, input validation, and limits to reduce data exposure.
learn how insecure design arises from missing best practices and cannot be fixed by perfect security controls, as shown by juice shop's sensitive data exposure and secure SDLC remedies.
Explore security misconfiguration, the fifth OWASP top vulnerability, and how misconfigured cloud permissions and default credentials expose apps. Learn remediation with server hardening, feature reduction, patching, containerization, and security headers.
Identify vulnerable and outdated components in web applications. Learn to report vulnerabilities and remediate by upgrading vulnerable libraries and applying security patches.
Explore identification and authentication failures, including brute force defenses, default and weak passwords, session ID exposure, and the importance of multifactor authentication and strong password policies.
Explore software and data integrity failures in supply chains, focusing on updates, libraries, and pipelines from untrusted sources, and use official repos, code reviews, and digital signatures.
Learn how security logging and monitoring failures occur and implement robust logging, alerting, and Splunk-based SIEM controls to detect, respond to, and audit incidents.
Explore server side request forgery and how attackers coerce apps to access arbitrary destinations, including local and internal resources, with remediation via input validation and disable redirects.
Explore information security careers from devsecops and cloud penetration testing to container security and security architecture and design, covering threat modeling, web and mobile penetration testing, and cloud GDPR compliance.
Course Updates:
v 1.0 - July 2025
Updated course with OWASP Juice Shop latest Challenge links
v 1.0 - July 2023
Updated course with Coding Examples for OWASP Top 10 Security vulnerabilities and Recommendations as a Security Engineer
Updated course with Interview Questions and Answers for the position of Security Engineer
Updated course with Quiz to check the OWASP TOP 10 2021 knowledge
Updated course with Security Engineer Sample CV
Who shall take this course?
This "OWASP TOP 10 Fundamentals" course is designed for Security Engineers, Security Architects, Software Developers, QA Professionals and Freshers looking to find a job in the field of security. This course builds the foundation of security domain and helps to answers all the questions that are asked during security position interview.
Learn about security vulnerabilities that are identified in DevSecOps pipelines, get Hands On experience in using Security tools & technologies like Burp Suite.
This course is for:
Developers
DevOps
Security Engineers
Aspiring professional in the Security domain
Quality Assurance Engineers
InfoSec/AppSec Professional
Why purchase this course?
This is only practical hands-on OWASP TOP 10 - 2021 course available on the internet till now.
By the end of the course, you will be able to successfully answer any interview questions around OWASP Top 10 and hence, you will be able to start your security journey. At the end of this course, you will be able to choose your career in the application security area and you will be able to implement the learnings from this course in your project.
No Action required before taking this course. For any question or concerns, Please post your comments on discussions tab
Disclaimer: English subtitles are auto-generated so please ignore any grammar mistakes