Skip to content

Level 2 · Web Application Testing

The web is where most real-world findings live, and it is also the easiest place to practise legally: you can run a deliberately vulnerable app on your own machine and attack it to your heart's content. This level works entirely against DVWA and OWASP Juice Shop — apps built to be broken — so every technique here is something you can reproduce without touching anyone else's system.

You will learn to think like a web tester: map the app, intercept and modify its traffic, and work methodically through the OWASP Top 10 classes of flaw — proving each one in a way that shows impact without destroying data, and noting the fix alongside every finding.

Modules

  1. How Web Apps Work & the Testing Mindset — requests, responses, state, and where trust boundaries sit.
  2. Using an Intercepting Proxy — Burp Suite and OWASP ZAP: capture, modify and replay requests.
  3. Injection Flaws & SQL Injection — how untrusted input becomes code, demonstrated safely in DVWA, and the parameterised-query fix.
  4. Cross-Site Scripting (XSS) — reflected, stored and DOM XSS, impact, and output encoding + CSP as the defence.
  5. Broken Authentication & Sessions — credential handling, session fixation, and rate limiting.
  6. Broken Access Control & IDOR — the most common serious flaw: acting outside your permissions.
  7. SSRF, File Upload & Path Traversal — tricking the server into fetching, storing or reading what it should not.
  8. Misconfiguration & Vulnerable Components — defaults, headers, and outdated dependencies.
  9. API Security Testing — REST and GraphQL endpoints, auth, object-level authorization and rate limits.
  10. Project — Assessing OWASP Juice Shop — a structured assessment with a written findings report.