DAY 3

Web Application Security

Understand how web applications work, where common weaknesses occur and how secure coding prevents them.

01

Web Application Fundamentals

Understand the browser-server-application-database path before studying web security.

45 min · Architecture visualization
Open →
02

Build a Training Web Application

Understand the components of a simple registration/login/profile application used for later security lessons.

50 min · Application walkthrough
Open →
03

HTTP Request & Response Analysis

Inspect methods, headers, cookies, parameters and status codes in normal web traffic.

55 min · Browser DevTools inspection
Open →
04

Burp Suite Fundamentals

Understand how an intercepting proxy sits between a browser and an authorized training application.

45 min · Proxy flow visualization
Open →
05

OWASP Web Security Risks

Learn common categories of web application weaknesses and their defensive controls.

60 min · Scenario classification
Open →
06

SQL Injection & Database Security

Understand why unsafe query construction is dangerous and how parameterized queries separate code from data.

65 min · Secure-query exercise
Open →
07

Cross-Site Scripting & Output Security

Understand how untrusted content reaches HTML output and how encoding/sanitization prevents browser interpretation.

55 min · Sandboxed output-safety demo
Open →
08

Authentication & Session Security

Learn how password verification, sessions, cookies and logout protect authenticated workflows.

60 min · Session-flow inspection
Open →
09

Authorization & Access Control

Understand why authenticated users still need role and permission checks before accessing resources.

50 min · Role-check walkthrough
Open →