Skip to content
CyberEd DZ

Web Application Security

Medium

How web apps break, and how to design them so they do not.

Courses:
14 sections
2.4 h
Intermediate English

Course content is in English (Intermediate English). The interface, summaries and glossary are in your language.

Log in to start this course

Log in

What you will be able to do

  • Find and explain access-control flaws
  • Explain injection and the fix that actually works
  • Write a finding a developer can act on

Recommended background

These are suggestions, not requirements. You can start now.

Course outline

  1. Module 1

    How the Web Works

    1. HTTP in Depth 8 min
    2. Cookies and Sessions 11 min
    3. The Same-Origin Policy 14 min
  2. Module 2

    Your Lab

    1. Set Up Juice Shop Locally Lab 8 min
    2. Using an Intercepting Proxy 11 min
  3. Module 3

    Broken Access Control

    1. IDOR 8 min
    2. Privilege Escalation 11 min
    3. Designing It Right 14 min
  4. Module 4

    Injection

    1. SQL Injection Mechanics 8 min
    2. Parameterised Queries as the Fix 11 min
  5. Module 5

    Cross-Site Scripting

    1. Reflected, Stored and DOM XSS 8 min
    2. Output Encoding and CSP 11 min
  6. Module 6

    Reporting a Finding

    1. Writing for Developers 8 min
    2. Severity Without Drama 11 min

Written by CyberEd DZ