Przejdź do głównej treści
QA

Chwała Ukrainie!

Wróć do wszystkich kursów

Praktyczny kurs QA

Security Testing: Authorized Web and API Assessment

A practical course from written scope, HTTP and TLS, and threat modeling through controlled testing of authentication, sessions, authorization, injection, browser and server boundaries, APIs, dependencies, and remediation.

16 sesjiPełny kurs · bezpłatnie

Opis kursu

Nad czym będziesz pracować

A practical course from written scope, HTTP and TLS, and threat modeling through controlled testing of authentication, sessions, authorization, injection, browser and server boundaries, APIs, dependencies, and remediation.

Course curriculum

Explore the full learning path.

Explore lesson and topic titles here. Register and sign in to read the materials and take the knowledge checks for free.

Lesson 11. Authorization, scope, and rules of engagement

Theory, local laboratories, and evidence

  • ArticleMaking a security test authorized, controlled, and reproducible
  • Knowledge checkApplied checkpoint
Lesson 22. HTTP, TLS, and trust boundaries

Theory, local laboratories, and evidence

  • ArticleHow a request reaches data and where trust changes
  • Knowledge checkApplied checkpoint
Lesson 33. Threat modeling and attack surface

Theory, local laboratories, and evidence

  • ArticleFrom a system model to prioritized testable threats
  • Knowledge checkApplied checkpoint
Lesson 44. Burp Suite and OWASP ZAP in a local lab

Theory, local laboratories, and evidence

  • ArticleA scoped proxy workflow, passive findings, and manual confirmation
  • Knowledge checkApplied checkpoint
Lesson 55. Authentication and account recovery

Theory, local laboratories, and evidence

  • ArticleTesting the identity lifecycle without bulk login attempts
  • Knowledge checkApplied checkpoint
Lesson 66. Sessions, tokens, and CSRF

Theory, local laboratories, and evidence

  • ArticleSession lifecycle, cookie boundaries, and protection of state-changing requests
  • Knowledge checkApplied checkpoint
Lesson 77. Authorization and access control

Theory, local laboratories, and evidence

  • ArticleObject, function, and property permissions in a two-user matrix
  • Knowledge checkApplied checkpoint
Lesson 88. Injection and the data–interpreter boundary

Theory, local laboratories, and evidence

  • ArticleSafe canaries, parameterization, and least privilege
  • Knowledge checkApplied checkpoint
Lesson 99. XSS and browser security boundaries

Theory, local laboratories, and evidence

  • ArticleOutput contexts, DOM sinks, sanitization, CSP, and safe evidence
  • Knowledge checkApplied checkpoint
Lesson 1010. Server-side input, URL, file, and parser boundaries

Theory, local laboratories, and evidence

  • ArticleSSRF, path traversal, uploads, XXE, and deserialization in a controlled laboratory
  • Knowledge checkApplied checkpoint
Lesson 1111. Comprehensive API security testing

Theory, local laboratories, and evidence

  • ArticleInventory, contracts, authorization, resource limits, and business flows
  • Knowledge checkApplied checkpoint
Lesson 1212. Security configuration, TLS, and error handling

Theory, local laboratories, and evidence

  • ArticleSecure defaults from edge to application and evidence without secret disclosure
  • Knowledge checkApplied checkpoint
Lesson 1313. Business logic, abuse, and concurrency

Theory, local laboratories, and evidence

  • ArticleTesting workflow invariants, replay, idempotency, and race conditions
  • Knowledge checkApplied checkpoint
Lesson 1414. Dependencies, secrets, and the software supply chain

Theory, local laboratories, and evidence

  • ArticleFrom source and lockfile to SBOM, provenance, artifact, and deployment
  • Knowledge checkApplied checkpoint
Lesson 1515. Detection, reporting, and remediation

Theory, local laboratories, and evidence

  • ArticleTurning evidence into a reproducible risk decision and a closed defect
  • Knowledge checkApplied checkpoint
Lesson 1616. Security assessment capstone

Theory, local laboratories, and evidence

  • ArticleA complete authorized local SecurityLab assessment from charter to retest
  • Knowledge checkApplied checkpoint