Skip to content
Intermediate Web security Certificate

Web Application Security

Find, verify and fix the vulnerability classes that actually appear in web applications.

6 weeks 34 lessons 18 practical labs
Overview
The most immediately employable course in the catalogue. Web applications are where most real-world security work happens, and this course is built around the classes of flaw we find in engagements.

Every module ends with the remediation, not the exploit. You are graded on the fix.
Outcomes

What you will learn

Injection across SQL, NoSQL, command and template contexts
Cross-site scripting in all three variants
Broken access control and IDOR
Authentication and session management flaws
CSRF, SSRF and request forgery generally
File upload and deserialisation issues
Business logic abuse
Writing a professional web application report
Before you start

Requirements

  • Introduction to Ethical Hacking or equivalent
  • Basic understanding of HTTP and HTML
  • Any programming experience helps but is not required
Who teaches it
C

CyberKnight Faculty

Security engineers and assessors

Courses are written and taught by the same people who run our client engagements. What we find in real assessments becomes the lab material here, with client details removed.

Questions

About this course

Yes. On completion you receive a certificate listing the modules covered and the lab work completed. It reflects what you actually did rather than attendance.
You get direct instructor support. Ask on WhatsApp or Telegram and a person answers — usually the same day. Nobody here will make you feel foolish for asking something basic.
Only with written authorisation from whoever owns them. The techniques are taught for authorised assessment and defensive work. Running them against systems without permission is a criminal offence in most countries, regardless of your intent.