Course Summary

EC-Council’s Web Application Hacking and Security is a specialization certification that enables the cybersecurity workforce to learn, hack, test, and secure web applications from existing and emerging security threats in the industry verticals.

What you will learn:
• Advanced Web Application Penetration Testing
•Advanced SQL Injection (SQLi)
•Reflected, Stored and DOM-based Cross Site Scripting (XSS)
•Cross Site Request Forgery (CSRF) – GET and POST Methods
•Server-Side Request Forgery (SSRF)
•Security Misconfigurations
•Directory Browsing/Bruteforcing
•CMS Vulnerability Scanning
•Network Scanning
•Auth Bypass
•Web App Enumeration
•Dictionary Attack
•Insecure Direct Object Reference Prevention (IDOR)
•Broken Access Control
•Local File Inclusion (LFI)
•Remote File Inclusion (RFI)
•Arbitrary File Download
•Arbitrary File Upload
•Using Components with Known Vulnerabilities
•Command Injection
•Remote Code Execution
•File Tampering
•Privilege Escalation
•Log Poisoning
•Weak SSL Ciphers
•Cookie Modification
•Source Code Analysis
•HTTP Header modification
•Session Fixation
•Clickjacking

Prerequisites • Good understanding of web application working. • Basic working knowledge of the Linux command line. • Basic knowledge of OSes and file systems. • Basic knowledge of Bash and/or Python scripting.

Candidate will get 6 hours to solve multiple challenges and the exam will be remotely proctored online practical exam which will assesses candidates’ skills and proficiencies on a broad spectrum of OWASP Top-10 web application vulnerabilities and attack vectors. Candidate requires a deep understanding of various web application technologies, their inherent vulnerabilities, information gathering & Recon approach and manual exploitation techniques. The exam focuses on candidates’ proficiencies in performing a web application security assessment in real life stressful scenarios where time is limited. Candidates who score more than 60% will earn the Certified Web Application Security Associate certification, candidates who score more than 75% will be awarded the Certified Web Application Security Professional certification and candidates who score more than 90% attain the prestigious Certified Web Application Security Expert certification.

Following your booking, a confirmation message will be sent to all participants, ensuring you're well-informed of your successful enrollment. Calendar placeholders will also be dispatched to assist you in scheduling your commitments around the course. Rest assured, all course materials and access to necessary labs or platforms will be provided no later than one week before the course begins, allowing you ample time to prepare and engage fully with the learning experience ahead.

Our comprehensive training package includes all the necessary materials and resources to facilitate a full learning experience. Enrollees will be provided with detailed course content, encompassing a wide array of topics to ensure a thorough understanding of the subject matter. Additionally, participants will receive a certificate of completion to recognize their dedication and hard work. It's important to note that while the course fee covers all training materials and experiences, the examination fee for certification is not included but can be purchased separately.

Questions About This Course?