- World-class Lectures
- Free Mentorship
- Internship Opportunities
- Simplicity
- Free Certificate
- Unlimited Access
Learn how to identify bugs and security vulnerabilities in websites and applications - known as bug hunting - along with ethical hacking and penetration testing skills. A computer with minimum 4GB RAM is required.
What You Will Learn:
- Basic Linux Commands
- Installing Burp Suite
- Setup for Windows OS Users
- How the Internet Works: Server, Client, Request, Response
- Explanation of HTTP Status Codes
- What Are Bugs?
- Registering on Web Security Academy to Access Labs
- Google Dorking
- Subdomain Enumeration
- Content Discovery
Authentication Vulnerabilities
- Username Enumeration via Different Responses
- Username Enumeration via Subtly Different Responses
- Username Enumeration via Response Timing
- 2FA Simple Bypass
- 2FA Broken Logic
- Brute-forcing a Stay-Logged-In Cookie
- Offline Password Cracking
- Password Reset Poisoning via Middleware
Cross Site Scripting (XSS)
- Reflected XSS in HTML Context with No Encoding
- Stored XSS in HTML Context with No Encoding
- DOM XSS using `document.write` and `location.search`
Race Conditions Vulnerabilities
- Limit Overrun Race Conditions
- Bypassing Rate Limits via Race Conditions
Path Traversal Vulnerabilities
- Simple File Path Traversal
- Traversal Sequences Blocked with Absolute Path Bypass
Command Injection Vulnerabilities
- Basic OS Command Injection
Access Control Vulnerabilities
- Unprotected Admin Functionality
- Unprotected Admin with Unpredictable URL
- User Role Controlled via Request Parameter
- Modifiable User Role in Profile
- User ID Controlled via Request Parameter
- User ID with Unpredictable Identifiers
- User ID Leading to Data Leakage in Redirect
- User ID Leading to Password Disclosure
- Insecure Direct Object References
SQL Injection Vulnerabilities
- SQLi in WHERE Clause Allowing Hidden Data Retrieval
- SQLi for Login Bypass
File Upload Vulnerabilities
- Remote Code Execution via Web Shell Upload
CSRF Vulnerabilities
- CSRF Without Any Defenses
SSRF Vulnerabilities
- Basic SSRF to Local Server
- Basic SSRF to Another Backend System
- Real-World RXSS
- Using SQLMap
- Broken Link Hijacking
- CMS Hacking
- Open Redirect
- Subdomain Takeover
- Automated Vulnerability Scanning
What This Course Will Do for You:
- Understand key concepts of how the internet and websites work
- Learn how to discover security vulnerabilities in websites and apps
- Become a professional bug hunter
Requirements:
- A personal computer (minimum 4GB RAM)
- Basic knowledge of Cybersecurity
Instructor: Engr. Ibrahim Auwal
Level: Beginner, Intermediate, and Advanced
Engr. Ibrahim Auwal
Web expert and a professional Cybersecurity Analyst, well-trained in identifying security vulnerabilities in websites and apps, and has taught this skill to hundreds of people.
From Top Learners
this is the best course ever
thanks engr ibrahim very understadable
yanzu naga wajen zama a flowdiary, insha Allahu anan zamuyi nasara
Masha.
Alhamdulillah finally completed the course and i will confidently say i learned alot from the course , which has massively helped me build confidence around my capabilities
Masha Allah new on it kuma lecture anyin kyau sosai
Amin
MashaAllah Alhamdulillah,
Really appreciate 🙏
mashaa Allah karatu yana mana dadi
Masha Allah. Allah kara basira
Masha Allah.