Level 2 · Web Application Testing¶
The web is where most real-world findings live, and it is also the easiest place to practise legally: you can run a deliberately vulnerable app on your own machine and attack it to your heart's content. This level works entirely against DVWA and OWASP Juice Shop — apps built to be broken — so every technique here is something you can reproduce without touching anyone else's system.
You will learn to think like a web tester: map the app, intercept and modify its traffic, and work methodically through the OWASP Top 10 classes of flaw — proving each one in a way that shows impact without destroying data, and noting the fix alongside every finding.
Modules¶
- How Web Apps Work & the Testing Mindset — requests, responses, state, and where trust boundaries sit.
- Using an Intercepting Proxy — Burp Suite and OWASP ZAP: capture, modify and replay requests.
- Injection Flaws & SQL Injection — how untrusted input becomes code, demonstrated safely in DVWA, and the parameterised-query fix.
- Cross-Site Scripting (XSS) — reflected, stored and DOM XSS, impact, and output encoding + CSP as the defence.
- Broken Authentication & Sessions — credential handling, session fixation, and rate limiting.
- Broken Access Control & IDOR — the most common serious flaw: acting outside your permissions.
- SSRF, File Upload & Path Traversal — tricking the server into fetching, storing or reading what it should not.
- Misconfiguration & Vulnerable Components — defaults, headers, and outdated dependencies.
- API Security Testing — REST and GraphQL endpoints, auth, object-level authorization and rate limits.
- Project — Assessing OWASP Juice Shop — a structured assessment with a written findings report.