The primary focus is learning by doing, with each module focusing on real-world techniques. You will also receive 12-months access to the full on-demand version of the course to support the reinforcement of classroom learning objectives.
This course includes two Exam Vouchers for TCM Security’s Practical Web Pentest Associate (PWPA) and Practical Web Pentest Professional (PWPP) certifications. Each exam voucher includes 1 exam attempt and is valid for 12-months from the course completion date.
The fundamental architecture and functionality of web applications
Common server-side vulnerabilities and attack techniques
Client-side attack methods and exploitation tactics
Scanning tools and techniques used to identify and execute advanced web application attacks
Who should attend Web Penetration Testing Course
- Aspiring Penetration Testers and Cybersecurity Professionals
- Beginner web application penetration testers looking to validate their skills.
- People who have a keen interest in web applications and how they can be exploited.
- Individuals looking for extra guidance as they study for the PJPT or PWPA.
- Anyone looking to advance their knowledge, skills, and methodologies
- Intermediate-level web app pentesters who are looking to go beyond the fundamentals to understand how web apps work and what makes them vulnerable.
- Anyone with some experience in web application development looking to gain some experience with security.
- Students looking to prepare for the Practical Web Penetration Tester (PWPT) exam.
Prerequisites for Web Penetration Testing Course
Web Penetration Testing Course Outline
- Introduction
- How Web Apps Work
- Intro to HTTP
- Broken Authentication
- Broken Access Control
- SQL Injection
- SQL Injection
- Command Injection
- XML External Entity (XXE) Injection
- Directory Traversal
- File Upload
- Server-Side Request Forgery (SSRF)
- Cross-Site Scripting (XSS)
- Cross-Site Request Forgery (CSRF)
- Scanning, Filter Bypasses, WAF Bypasses
- Logic Bugs
- Building a Methodology
- Performing a Web App Pentest
Resources
FAQs on Web Penetration Testing
This course is designed for aspiring penetration testers, cybersecurity professionals, beginner and intermediate web app pentesters, developers interested in security, and those preparing for certifications like PJPT, PWPA, or PWPT.
No prior penetration testing or security knowledge is required. General computer use skills are sufficient to participate in this course.
The course runs for 4 days, covering web app fundamentals and server-side attacks on Day 1-2, client-side and additional server-side attacks on Day 3, and scanning techniques with advanced attack methodologies on Day 4.
Students will learn web application architecture, common server-side and client-side vulnerabilities, exploitation techniques, and scanning tools used to identify and execute advanced web application attacks.
Yes, this course is particularly useful for individuals studying for the Practical Junior Penetration Tester (PJPT), Practical Web Penetration Associate (PWPA), or Practical Web Penetration Tester (PWPT) certification exams.


