
Set up an attack machine and a targeted web server on your computer and network to safely practice web application hacking skills using common tools.
Set up a hacking lab by installing Oracle VirtualBox and extension pack, importing a Kali Linux VM, configuring bridge networking, and launching in full screen for safe open testing.
Set up a vulnerable web application in VirtualBox to practice penetration testing in your lab, using a Metasploit web app with brute force, sql injection, command execution, and csv inclusion.
Kick off a Kali Linux basics series that covers essential commands, keyboard shortcuts, and basic Linux tools for file manipulation, networking, permissions, piping, process management, and proxy chain.
Boost Linux terminal efficiency with practical keyboard shortcuts for Kali Linux. Open the terminal with ctrl-alt-t, manage tabs with ctrl-shift-t, clear with ctrl-l, and use autocomplete and ctrl-c/ctrl-z.
Master essential linux terminal basics for directory and file management, including pwd, cd, ls, cat, rm, mkdir, cp, mv, and navigating home, root prompts, and simple permissions.
Learn to use ssh, ping, ftp, and telnet in Kali Linux to communicate with remote systems, check connectivity, and transfer files.
Discover how to enumerate system information, including current user, user ID, hostname, kernel version, and Linux distribution details using commands like whoami, id, hostname, uname, hostnamectl, os-release, issue, and lsb_release.
Master Kali Linux's pre-installed tools by using quick one-liner queries like 'what is tool', the -h flag, and the man command, then focus on one or two tools.
Set up your virtual hacking lab and master essential web application penetration testing tools, including content discovery, network scanning, intercepting web requests, and using toolkits to obtain a reverse shell.
Learn to use Nmap for web server port scanning, version detection, and service discovery, including aggressive scans, specific port scans, and script-based checks.
Learn to use the DART web content discovery tool to locate hidden directories and files on a web server, enhancing web application testing and bug bounty hunts with word lists.
Explore a simple tool to generate a PHP shell payload and establish a reverse shell for testing web application vulnerabilities, including session recovery and remote command execution with netcat.
Learn to use the sub Mr. subdomain enumeration tool to discover subdomains, expand open testing and bug bounty scope, and save results to a text file for analysis.
Learn to use netcat to obtain a reverse shell in web application penetration testing, including setting up a listening mode and delivering payloads to a vulnerable web server.
Learn to use the http probe tool to enumerate subdomains and identify working http and https servers from a list, install the tool, and optionally specify ports.
Learn to intercept and manipulate web traffic with Burp Suite to test web applications, using proxy, intercept, repeater, intruder, sequencer, decoder, and compare against a target server.
Explore brute force variability on vulnerable web app, perform a controlled brute force attack using burp suite tool and intruder, and use a password list to reveal admin/password login.
Demonstrates command injection vulnerabilities by showing how input fields execute operating system commands on a web server, including ping and directory listing.
Learn file inclusion vulnerabilities and local file intrusion, showing how input manipulation reads sensitive server files like password data via directory traversal on a Linux web server.
Discover how file upload vulnerabilities enable attackers to upload and execute malicious files on a web server, and learn hands-on testing with a demo application to demonstrate a reverse shell.
Explore cross-site scripting vulnerability testing, distinguishing reflected and stored XSS, and learn how testers use payloads like script alert to detect reflections in input fields.
Welcome to Web Application Penetration Testing Basics course! This course will be 100% hands-on, focusing specifically on web application penetration testing & vulnerability assessments.
In this course you'll learn website / web applications vulnerabilities, web penetration testing tools, web app penetration testing and bug bounty hunting. This course assumes you have NO prior knowledge in penetration testing, and by the end of it you'll be at a high level, being able to discover bugs or vulnerabilities in websites like an professional penetration tester and secure them like security experts!
By Enrolling into this course you will Learn advance web application penetration testing like a Professional Penetration Tester & Bug Bounty Hunter. This course is highly practical but it won't neglect the theory, First We’ll be building a lab environment consisting of Kali Linux , and a intentionally vulnerable target web application server, what we will be using for practicing web penetration testing and learning different web vulnerabilities.
Also, we will learn in depth of all the professional tools use for web penetration testing and bug hunting one by one and become a master of those tools. I can assure after completing this course you will learn everything you required to become a professional web penetration tester & get into infosec.
So, what are you waiting for? Take this course and start learning now Web Application Penetration Testing and become a master of it. I’m waiting for you in the course lectures. If you have any questions during any of the labs, please feel free to reach out to me directly with the messaging system or Q&A section.
Notes:
This course is created for educational purposes only. This course is totally a product of Md Mehedi Hasan no other organization is associated with it or a certification exam. Although, you will receive a course completion certification from Udemy, apart from that NO OTHER ORGANISATION IS INVOLVED.
Thank You!