Web Application Security
Understand how web applications work, where common weaknesses occur and how secure coding prevents them.
Web Application Fundamentals
Understand the browser-server-application-database path before studying web security.
45 min · Architecture visualizationBuild a Training Web Application
Understand the components of a simple registration/login/profile application used for later security lessons.
50 min · Application walkthroughHTTP Request & Response Analysis
Inspect methods, headers, cookies, parameters and status codes in normal web traffic.
55 min · Browser DevTools inspectionBurp Suite Fundamentals
Understand how an intercepting proxy sits between a browser and an authorized training application.
45 min · Proxy flow visualizationOWASP Web Security Risks
Learn common categories of web application weaknesses and their defensive controls.
60 min · Scenario classificationSQL Injection & Database Security
Understand why unsafe query construction is dangerous and how parameterized queries separate code from data.
65 min · Secure-query exerciseCross-Site Scripting & Output Security
Understand how untrusted content reaches HTML output and how encoding/sanitization prevents browser interpretation.
55 min · Sandboxed output-safety demoAuthentication & Session Security
Learn how password verification, sessions, cookies and logout protect authenticated workflows.
60 min · Session-flow inspectionAuthorization & Access Control
Understand why authenticated users still need role and permission checks before accessing resources.
50 min · Role-check walkthrough