Skip to content
normSight — Cyber Security

Offensive Trainings

Web Application Penetration Testing Course

The Web Application Penetration Testing (WAPT) course teaches, hands-on, the techniques required to carry out a comprehensive and professional penetration test against modern web applications.

The Web Application Penetration Testing course (WAPT) is an online, self-paced training course providing all the advanced skills needed to carry out a comprehensive and professional penetration test against modern web applications.

Highly Practical

Thanks to extensive use of Hera Lab and coverage of the latest research in web application security, the WAPT course is not only the most practical training course on the subject but also the most current. Perform penetration tests against real-world web applications.

The Course at a Glance

  • Start from the fundamentals and progress through to advanced post-exploitation activity
  • Broad coverage of the OWASP Top 10
  • Master Burp Suite
  • In-depth web application analysis, information gathering and enumeration
  • XSS and SQL injection
  • Session-related vulnerabilities
  • LFI/RFI
  • HTML5 attacks
  • Penetration testing of content management systems (CMS)
  • Testing NoSQL databases and NoSQL-related APIs, and NoSQL injection
  • Start from web application attacks and move into network and infrastructure penetration testing
  • Gives you access to private forums
  • Makes you a professional web application penetration tester
  • Earning the eWPTv1 certification qualifies you for 40 CPE credits

Course Material

  • 78 labs in Hera Lab
  • 2344 slides
  • 5 hours of HQ video training material

Course Delivery

  • HTML5, PDF, MP4
  • Offline access available
  • Access from PC, tablet and smartphone

Curriculum

Module 1: The Penetration Testing Process

Module 2: Introduction to Web Applications

Module 3: Information Gathering

Module 4: Cross-Site Scripting

Module 5: SQL Injection

Module 6: Authentication and Authorisation

Module 7: Session Security

Module 8: Flash

Module 9: HTML5

Module 10: File and Resource Attacks

Module 11: Other Attacks

Module 12: Web Services

Module 13: XPath

Module 14: Penetration Testing Content Management Systems (CMS)

Module 15: Penetration Testing NoSQL Databases

  • Prerequisites

  • Basic knowledge of HTML, HTTP and JavaScript

  • Reading and understanding PHP code is not required but will help

  • Web development skills are not required

Who Can Attend

  • Penetration testing teams
  • Web developers
  • IT managers and staff

Frequently Asked Questions

What prior knowledge does this course require?

Familiarity with the HTTP protocol and basic web technologies is expected. Those entirely new to penetration testing are advised to start with the Penetration Testing Student programme.

Which vulnerability classes are covered?

Injection flaws, authentication and session management defects, authorisation bypass, file upload flaws, server-side request forgery and business logic errors are all worked through hands-on.

Is it based on automated tools?

No. Tools are introduced, but the focus of the course is manual testing methodology — how to find the business logic and authorisation flaws that automated tools miss.

See the real risks in your systems.

Talk to our team about a penetration test or training plan that fits your scope.