Web Penetration Testing

Skip to Scheduled Dates

Course Overview

This hands-on live training is designed to take you from beginner to confident web application pentester with no prior hacking experience required. You’ll gain a solid foundation in how web apps work, how to find and exploit common vulnerabilities, and how to think like an attacker.

The primary focus is learning by doing, with each module focusing on real-world techniques. You will also receive 12-months access to the full on-demand version of the course to support the reinforcement of classroom learning objectives.

This course includes two Exam Vouchers for TCM Security’s Practical Web Pentest Associate (PWPA) and Practical Web Pentest Professional (PWPP) certifications. Each exam voucher includes 1 exam attempt and is valid for 12-months from the course completion date.

Who Should Attend

  • Aspiring Penetration Testers and Cybersecurity Professionals
  • Beginner web application penetration testers looking to validate their skills.
  • People who have a keen interest in web applications and how they can be exploited.
  • Individuals looking for extra guidance as they study for the PJPT or PWPA.
  • Anyone looking to advance their knowledge, skills, and methodologies
  • Intermediate-level web app pentesters who are looking to go beyond the fundamentals to understand how web apps work and what makes them vulnerable.
  • People who have a keen interest in web applications and how they can be exploited.
  • Anyone with some experience in web application development looking to gain some experience with security.
  • Students looking to prepare for the Practical Web Penetration Tester (PWPT) exam.

Course Objectives

    • The fundamental architecture and functionality of web applications
    • Common server-side vulnerabilities and attack techniques
    • Client-side attack methods and exploitation tactics
    • Scanning tools and techniques used to identify and execute advanced web application attacks

Course Outline

Day 1 – How Web Apps Work

  • Introduction
  • How Web Apps Work
  • Intro to HTTP
  • Broken Authentication
  • Broken Access Control
  • SQL Injection

Day 2 – Server-Side Attacks

  • SQL Injection
  • Command Injection
  • XML External Entity (XXE) Injection
  • Directory Traversal

Day 3 – Server-Side Attacks and Client-Side Attacks

  • File Upload
  • Server-Side Request Forgery (SSRF)
  • Cross-Site Scripting (XSS)
  • Cross-Site Request Forgery (CSRF)

Day 4 – Scanning and More Advanced Attacks

  • Scanning, Filter Bypasses, WAF Bypasses
  • Logic Bugs
  • Building a Methodology
  • Performing a Web App Pentest

 Back to Course Search

Class Dates & Times

Class times are listed Eastern time

This is a 4-day class

Retail Price: $2,699.00

BRM Price: $2,294.15

Register When Time
 Register 08/22/2025 9:00AM - 5:00PM
 Register 11/21/2025 9:00AM - 5:00PM