Skip to content
normSight — Cyber Security

Offensive Trainings

Web Application Penetration Testing eXtreme

The WAPTX course builds the ability to find advanced web vulnerabilities that standard methods miss, and to develop bespoke exploits for them.

WAPTX comes with lifetime access to course materials and flexible access to the most advanced virtual labs in network and web application security.

Highly Practical

Perform penetration tests against a set of real-world web applications. WAPTX includes the most advanced virtual lab in network and web application security: Hera Lab.

The Course at a Glance

  • The most advanced course on web application penetration testing
  • Based on the techniques used by professional penetration testers
  • Master advanced web application attacks and security tools
  • Detailed analysis of web application vulnerabilities
  • Covers XSS, SQL injection, HTML5 and much more
  • In-depth obfuscation and encoding techniques
  • Filter bypass and WAF evasion techniques
  • Discover HTML5 and XML attack vectors and exploits
  • Discover advanced PHP, Java, deserialisation, LDAP, server-side and authentication/SSO attacks
  • Learn effective penetration testing of APIs and cloud-backed applications
  • Detecting Java RCE internals, attacking RMI-based JMX services, JNDI injection attacks, PHP object instantiation, PHP type juggling, building property-oriented programming chains, and attacking memory-unsafe languages
  • Access to private forums
  • Makes you an advanced web application penetration tester

Course Material

  • HQ video training material
  • 1750+ slides
  • 70+ Hera labs

Course Delivery

  • Self-paced / HTML5, PDF, MP4
  • Offline access available
  • Access from PC, tablet and smartphone

Curriculum

Module 1: Encoding and Filtering

Module 2: Evasion Fundamentals

Module 3: Cross-Site Scripting (XSS)

Module 4: XSS – Escaping Filters and Bypassing WAFs

Module 5: Cross-Site Request Forgery (CSRF)

Module 6: HTML5

Module 7: SQL Injection

Module 8: SQLi – Escaping Filters and Bypassing WAFs

Module 9: XML Attacks

Module 10: Serialisation Attacks

Module 11: Server-Side Attacks

Module 12: Cryptographic Attacks

Module 13: Authentication and SSO Attacks

Module 14: Penetration Testing APIs and Cloud Applications

Module 15: LDAP-Based Application Attacks

Prerequisites

  • In-depth knowledge of HTML, HTTP, server-side languages, XML and JavaScript
  • A good understanding of, and practical competence in, XSS, CSRF, SQL and basic HTML5 attacks
  • The ability to read and understand PHP code will help, though it is not mandatory
  • Basic development skills are required

Who Can Attend

  • Penetration testers
  • Web developers
  • IT managers and staff

Labs

The WAPT course is a practice-based curriculum. Integrated with Hera Lab, the most advanced virtual lab in IT security, this product offers an unmatched practical learning experience. Hera is the only virtual lab that provides each student with fully isolated access to every real-world network scenario on the platform. Students can access Hera Lab from anywhere over VPN.

Lab IDDescriptionCategory
Lab 1Introduction – 2 challenge labsInstructional
Lab 2Information Gathering – 2 challenge labsInstructional
Lab 3Cross-Site Scripting – 7 challenge labsInstructional
Lab 4SQL Injection – 10 challenge labsInstructional
Lab 5Authentication and Authorisation – 14 challenge labsInstructional
Lab 6Session Security – 9 challenge labsInstructional
Lab 7Flash Security – 1 challenge labInstructional
Lab 8HTML5 – 4 challenge labsInstructional
Lab 9File and Resource Attacks – 4 challenge labsInstructional
Lab 10Other Attacks – 1 challenge labInstructional
Lab 11Web Services – 4 challenge labsInstructional
Lab 12XPath – 5 challenge labsInstructional
Lab 13Exploiting WordPress – 5 challenge labsInstructional
Lab 14Exploiting WordPress from Static Analysis – 1 challenge labInstructional
Lab 15Chaining Vulnerabilities to Remotely Obtain WP Admin Credentials – 1 challenge labInstructional
Lab 16Exploiting Redis – 3 challenge labsInstructional
Lab 17NoSQL Injection Against MongoDB – 4 challenge labsInstructional
Lab 18CouchDB Exploitation – 2 challenge labsInstructional

Frequently Asked Questions

What is the difference between WAPT and WAPTX?

WAPT teaches how to run a comprehensive, professional web application penetration test. WAPTX is the advanced level: it focuses on filter and defence evasion, chained exploitation and developing custom exploits.

What are the prerequisites?

Experience in web application security, a firm grasp of HTTP and the browser security model, and scripting ability are expected.

Which topics are covered?

Advanced injection techniques, deserialisation flaws, cryptographic weaknesses, bypassing security filters, and chaining vulnerabilities to amplify their impact.

See the real risks in your systems.

Talk to our team about a penetration test or training plan that fits your scope.