Learn web application penetration testing from beginner to advanced. This course is perfect for people who are interested in cybersecurity or ethical hacking.
Resources:
Burp Suite: https://portswigger.net/burp
WAFW00F: https://github.com/EnableSecurity/wafw00f
OWASP SAP: https://www.zaproxy.org
Metasploit: https://github.com/rapid7/metasploit-framework/wiki/Nightly-Installers
Kali Linux: https://www.kali.org/downloads/
OWASP Juice Shop https://owasp.org/www-project-juice-shop
Damn Vulnerable Web Application (DVWA): http://www.dvwa.co.uk
Course Contents:
00:00:00 - Setting Up Burp Suite
00:08:07 - Spidering & DVWA
00:19:04 - Brute Force Attacks With Burp Suite
00:32:55 - Target Scope And Spidering
00:46:32 - Discovering Hidden Files With ZAP
01:04:24 - Web Application Firewall Detection with WAFW00F
01:12:28 - DirBuster
01:25:27 - XSS(Reflected, Stored & DOM)
01:41:22 - CSRF (Cross Site Request Forgery)
02:02:42 - Cookie Collection & Reverse Engineering
02:14:17 - HTTP Attributes (Cookie Stealing)
02:27:48 - SQL Injection