Security Testing: Authorized Web and API Assessment
A practical course from written scope, HTTP and TLS, and threat modeling through controlled testing of authentication, sessions, authorization, injection, browser and server boundaries, APIs, dependencies, and remediation.
16 mācību sesijasPilns kurss · bezmaksas
Kursu apskats
Pie kā strādāsi
A practical course from written scope, HTTP and TLS, and threat modeling through controlled testing of authentication, sessions, authorization, injection, browser and server boundaries, APIs, dependencies, and remediation.
Course curriculum
Explore the full learning path.
Explore lesson and topic titles here. Register and sign in to read the materials and take the knowledge checks for free.
01Lesson 11. Authorization, scope, and rules of engagement+
Theory, local laboratories, and evidence
ArticleMaking a security test authorized, controlled, and reproducible
Knowledge checkApplied checkpoint
02Lesson 22. HTTP, TLS, and trust boundaries+
Theory, local laboratories, and evidence
ArticleHow a request reaches data and where trust changes
Knowledge checkApplied checkpoint
03Lesson 33. Threat modeling and attack surface+
Theory, local laboratories, and evidence
ArticleFrom a system model to prioritized testable threats
Knowledge checkApplied checkpoint
04Lesson 44. Burp Suite and OWASP ZAP in a local lab+
Theory, local laboratories, and evidence
ArticleA scoped proxy workflow, passive findings, and manual confirmation
Knowledge checkApplied checkpoint
05Lesson 55. Authentication and account recovery+
Theory, local laboratories, and evidence
ArticleTesting the identity lifecycle without bulk login attempts
Knowledge checkApplied checkpoint
06Lesson 66. Sessions, tokens, and CSRF+
Theory, local laboratories, and evidence
ArticleSession lifecycle, cookie boundaries, and protection of state-changing requests
Knowledge checkApplied checkpoint
07Lesson 77. Authorization and access control+
Theory, local laboratories, and evidence
ArticleObject, function, and property permissions in a two-user matrix
Knowledge checkApplied checkpoint
08Lesson 88. Injection and the data–interpreter boundary+
Theory, local laboratories, and evidence
ArticleSafe canaries, parameterization, and least privilege
Knowledge checkApplied checkpoint
09Lesson 99. XSS and browser security boundaries+
Theory, local laboratories, and evidence
ArticleOutput contexts, DOM sinks, sanitization, CSP, and safe evidence
Knowledge checkApplied checkpoint
10Lesson 1010. Server-side input, URL, file, and parser boundaries+
Theory, local laboratories, and evidence
ArticleSSRF, path traversal, uploads, XXE, and deserialization in a controlled laboratory
Knowledge checkApplied checkpoint
11Lesson 1111. Comprehensive API security testing+
Theory, local laboratories, and evidence
ArticleInventory, contracts, authorization, resource limits, and business flows
Knowledge checkApplied checkpoint
12Lesson 1212. Security configuration, TLS, and error handling+
Theory, local laboratories, and evidence
ArticleSecure defaults from edge to application and evidence without secret disclosure
Knowledge checkApplied checkpoint
13Lesson 1313. Business logic, abuse, and concurrency+
Theory, local laboratories, and evidence
ArticleTesting workflow invariants, replay, idempotency, and race conditions
Knowledge checkApplied checkpoint
14Lesson 1414. Dependencies, secrets, and the software supply chain+
Theory, local laboratories, and evidence
ArticleFrom source and lockfile to SBOM, provenance, artifact, and deployment
Knowledge checkApplied checkpoint
15Lesson 1515. Detection, reporting, and remediation+
Theory, local laboratories, and evidence
ArticleTurning evidence into a reproducible risk decision and a closed defect
Knowledge checkApplied checkpoint
16Lesson 1616. Security assessment capstone+
Theory, local laboratories, and evidence
ArticleA complete authorized local SecurityLab assessment from charter to retest