Penetration Testing
Web Application Penetration Testing
Find real vulnerabilities and write findings developers can fix.
- 10 modules
- 20 labs
- ~32 hours
- Advanced

- Hands-on Labs
- Projects
- Certificate
Course overview
An advanced, hands-on offensive course covering the modern web attack surface: authentication, access control, injection, SSRF, deserialisation and business logic flaws.
You test intentionally vulnerable applications you deploy yourself, then produce professional findings with reproduction steps, impact and remediation.
What you will be able to do
- Run a structured web application penetration test
- Exploit access control, injection and SSRF classes reliably
- Chain low-severity issues into meaningful impact
- Write findings with accurate CVSS and remediation guidance
- Produce a client-quality penetration test report
Curriculum
- 1
Methodology & Scoping
Test with a plan and stay in scope.
- Testing methodology
- Scope and rules of engagement
- Legal and ethical boundaries
- 2
Recon & Mapping
Understand the application before attacking it.
- Content discovery
- Auth flow mapping
- API surface enumeration
- 3
Authentication & Session Attacks
Break the front door.
- Credential attacks
- Session fixation and hijacking
- MFA bypass patterns
- JWT flaws
- 4
Access Control & Business Logic
The highest-impact findings in most tests.
- IDOR
- Privilege escalation
- Workflow abuse
- Race conditions
- 5
Injection & Server-Side Attacks
Get the server to work for you.
- SQL injection
- Command injection
- SSRF
- Template injection
- Deserialisation
- 6
Reporting & Remediation
The deliverable is the job.
- Writing a finding
- CVSS scoring
- Executive summary
- Retest procedure
Labs you will build
PrimeSec does not hand you a pre-built machine. You get professional lab guides and build the environment yourself — that is where the skill comes from.
- Deploy a vulnerable application stack locally
- Map an application's full authenticated surface
- Exploit an IDOR to access another tenant's data
- Extract data via blind SQL injection
- Escalate SSRF to internal service access
- Bypass a flawed MFA implementation
- Chain three low findings into a critical
- Write and peer-review a finding
Portfolio projects
- A complete penetration test report for a target application
- A reusable testing checklist and methodology document
- A remediation retest summary
Frequently asked questions
Do you provide the lab environment?
No — and that is intentional. PrimeSec gives you professional lab guides that teach you to build and configure the environment yourself using your own machine, Hyper-V, VMware, VirtualBox, Docker, or a cloud free tier. Building and troubleshooting the environment is part of the skill.
Is this course self-paced?
Web Application Penetration Testing is self-paced. Lessons, knowledge checks, labs and projects unlock in order so you always know what to do next.
Do I get a certificate?
You receive a PrimeSec course completion certificate once every module, lab and project requirement is met. It demonstrates completion and practical work — not an accredited industry certification.
Will cloud labs cost me money?
Labs are designed around free tiers and local virtualisation wherever possible, and every cloud lab includes cleanup steps so you do not leave billable resources running.
