PRACTICAL EXAM
At the end of the course, the participants will take a practical exam, in which the objective will be to perform a Penetration Testing and present a final report. After passing the exam, the designation and diploma of "CSA Web Penetration Tester (CWPT)" will be issued.
Meet your trainer
Cristian Cornea
Trainer
Course curriculum
-
-
THEORETICAL MODULE: Web Pentesting Methodology
-
THEORETICAL MODULE: Pre-engagement process (Defining the scope, setting up the testing environment, SoW, RoE, NDA, etc.)
-
THEORETICAL MODULE: OWASP TOP 10 – Web
-
THEORETICAL MODULE: OWASP TOP 10 – API
-
PRACTICAL MODULE: Enumeration and Reconnaissance
-
PRACTICAL MODULE: Using Automated Tools
-
PRACTICAL MODULE: CMS Scanning
-
PRACTICAL MODULE: Introduction to Burp Suite Community
-
PRACTICAL MODULE: User Enumeration and Validation
-
PRACTICAL MODULE: Identifying and Exploiting Vulnerable Components
-
PRACTICAL MODULE: Identifying and Exploiting Configuration Mistakes
-
PRACTICAL MODULE: Session Management Security Issues
-
PRACTICAL MODULE: Identification and Exploitation of Authentication Vulnerabilities
-
PRACTICAL MODULE: Identifying and Exploiting Vulnerabilities in the File Upload Functionality
-
PRACTICAL MODULE: Identifying and Exploiting Cross-Site Scripting (XSS) and HTML Injection Vulnerabilities
-
PRACTICAL MODULE: Identifying and Exploiting SQL Injection Vulnerabilities
-
PRACTICAL MODULE: Identifying and Exploiting XML External Entities Injection (XXE) Vulnerabilities
-
PRACTICAL MODULE: Identifying and exploiting Cross-Site Request Forgery (CSRF) Vulnerabilities
-
-
-
PRACTICAL MODULE: Identifying and exploiting Remote Code Execution (RCE) Vulnerabilities
-
PRACTICAL MODULE: Identifying and Exploiting Command Injection Vulnerabilities
-
PRACTICAL MODULE: Identifying and Exploiting Open Redirect Vulnerabilities
-
PRACTICAL MODULE: Identifying and Exploiting Remote File Inclusion (RFI) and Local File Inclusion (LFI) Vulnerabilities
-
PRACTICAL MODULE: Identifying and Exploiting Server-Side Request Forgery (SSRF) Vulnerabilities
-
PRACTICAL MODULE: Identifying and Exploiting CSV/Formula Injection Vulnerabilities
-
PRACTICAL MODULE: Identifying and Exploiting Broken Access Controls and Insecure Direct Object Reference (IDOR) Vulnerabilities
-
PRACTICAL MODULE: Identifying and Exploiting Deserialization Vulnerabilities
-
PRACTICAL MODULE: Identifying and Exploiting CRLF Injection Vulnerabilities
-
PRACTICAL MODULE: Identifying and Exploiting Server-Side Template Injection (SSTI) Vulnerabilities
-
PRACTICAL MODULE: Identifying and Exploiting Host Header Injection Vulnerabilities
-
PRACTICAL MODULE: Identifying and Exploiting Specific GraphQL Vulnerabilities
-
PRACTICAL MODULE: Identifying and Exploiting Specific API Vulnerabilities
-
PRACTICAL MODULE: Automating manual checks/Automatizarea Verificărilor Manuale
-
PRACTICAL MODULE: Creating a Web Penetration Testing Report
-
About this course
- 1.575 lei (or aprox. 315 EUR)
- 2 days
- Online