Offensive Security
Web Application Penetration Testing
Work through the OWASP Top 10 the way an assessor does — against a deliberately vulnerable target, with the same tooling and reporting discipline we use on client engagements.
What you'll be able to do
- Map and enumerate an application's real attack surface
- Find and exploit injection, access-control and authentication flaws
- Chain low-severity findings into a demonstrable business impact
- Write a finding the way a client will actually act on it
Agenda
- Recon and mapping · scoping an application honestly
- Injection: SQL, command, template
- Broken access control and IDOR at scale
- Authentication, session handling and JWT failures
- Reporting: severity, evidence and remediation that lands
- Tools
- Burp Suite Community, OWASP ZAP, ffuf, browser dev tools
- Prerequisites
- Comfortable with HTTP, basic Linux command line. No prior pentesting required.
- Lab requirements
- Laptop with 8 GB RAM, admin rights, and virtualization enabled. Lab VM image supplied a week ahead.
- Who it's for
- Developers, QA engineers, and security analysts moving into offensive work.