← All courses
intermediate
Web Exploitation Mastery.
The web attack surface end to end — how vulnerabilities arise, how to find them methodically, and how to report them, practised on isolated targets.
1The web attacker's mapfree
2Authentication & sessions
- Where auth breaksreading
- Sessions & JWTwalkthrough
3Injection
- The injection mindsetreading
- SQL injection, methodicallywalkthrough
- Command injectionreading
4Access control
- IDOR & broken object-level authwalkthrough
- Privilege & function-level controlreading
5Server-side flaws
- SSRFreading
- XXE, SSTI, file uploadreading
6Client-side
- XSS & the browser trust modelwalkthrough
- CSRF & friendsreading
7Chaining & reporting
- Bugs compoundreading
- The reportwalkthrough
8Appendix · — Defender's note
- Appendix · — Defender's notereading