Course ยท Pro
Web Application Security
By Wanderson Leandro de Oliveira
Web application security is not a checklist you run once โ it is a way of reading code that most developers never learn. This course teaches the OWASP Top 10 the way it should be taught: by understanding why an attack works before you learn how to stop it. You will practice every exploit against local, intentionally vulnerable applications (DVWA and OWASP Juice Shop, run via Docker on your own machine) โ never against real sites. By the end you will be able to spot SQL injection, XSS, CSRF, broken authentication, IDOR, SSRF and security misconfiguration in a code review, explain the fix, and apply it. The course closes with a practical hardening project on a deliberately vulnerable app.
Course content
OWASP fundamentals
- ๐ OWASP Top 10 in depth text
- ๐ Anatomy of a web attack text
- ๐ Setting up a safe practice target text
Injection attacks
- ๐ SQL Injection explained text
- ๐ Preventing SQL Injection with parameterized queries text
- ๐ Command injection and other injection types text
Client-side vulnerabilities
- ๐ Cross-Site Scripting (XSS) explained text
- ๐ Preventing XSS with output encoding and CSP text
- ๐ Cross-Site Request Forgery (CSRF) text
Authentication and session
- ๐ Broken authentication patterns text
- ๐ Secure session management text
- ๐ Insecure Direct Object References (IDOR) text
Configuration and infrastructure
- ๐ Security misconfiguration text
- ๐ Security headers essentials text
- ๐ SSRF and untrusted redirects text
Practice and project
- ๐ API security essentials text
- ๐ Secure code review checklist text
- ๐ Practical project: hardening a vulnerable app text