Course ยท Pro

Web Application Security

By Wanderson Leandro de Oliveira

Web application security is not a checklist you run once โ€” it is a way of reading code that most developers never learn. This course teaches the OWASP Top 10 the way it should be taught: by understanding why an attack works before you learn how to stop it. You will practice every exploit against local, intentionally vulnerable applications (DVWA and OWASP Juice Shop, run via Docker on your own machine) โ€” never against real sites. By the end you will be able to spot SQL injection, XSS, CSRF, broken authentication, IDOR, SSRF and security misconfiguration in a code review, explain the fix, and apply it. The course closes with a practical hardening project on a deliberately vulnerable app.

Course content

OWASP fundamentals

Injection attacks

Client-side vulnerabilities

Authentication and session

Configuration and infrastructure

Practice and project