Skip to content
Lyon & Fiurex
← Select your course
Intermediate

Junior Pentester + Web App Pentesting

Core technical skills to succeed as a junior penetration tester — security assessments against web applications and enterprise infrastructure.

Overview

  • •Authentication Attacks
  • •Injection Attacks
  • •Advanced Server-Side Attacks
  • •Advanced Client-Side Attacks
  • •HTTP Request Smuggling

Select your module(s)

You can select the modules you want to learn. There's a recommended order in the learning curve, unless you already know something and want to go further.

1
Intro to Web Hacking + Authentication
Hours: 24 hours
$1,144.82 USD/mo

Master exploiting authentication mechanisms through real-world scenarios, covering enumeration and brute force, session management, OAuth, MFA/2FA and JWT vulnerabilities.

  • Walking An Application
  • Content Discovery
  • Subdomain Enumeration
  • Authentication Bypass
  • IDOR
  • File Inclusion
  • Intro to SSRF
  • Intro to Cross-site Scripting
  • Race Conditions
  • Command Injection
  • SQL Injection
  • Enumeration & Brute Force — Enumerate and brute force authentication mechanisms.
  • Session Management — Learn about session management and the different attacks that can be performed against insecure implementations.
  • JWT Security — Learn about JWTs, where they are used, and how they need to be secured.
  • OAuth Vulnerabilities — Learn how the OAuth protocol works and master techniques to exploit it.
  • Multi-Factor Authentication — Exploiting Multi-Factor Authentication.
  • Hammer — Use your exploitation skills to bypass authentication mechanisms on a website and get RCE.
2
Burp Suite + Injection Attacks
Hours: 14 hours
$887.24 USD/mo

Master the skills of injection attacks, covering Advanced SQL Injection, Server-Side Template Injection, XXE Injection, LDAP Injection, and NoSQL Injection.

  • Burp Suite: The Basics
  • Burp Suite: Repeater
  • Burp Suite: Intruder
  • Burp Suite: Other Modules
  • Burp Suite: Extensions
  • Advanced SQL Injection — Learn advanced injection techniques to exploit a web app.
  • NoSQL Injection — A walkthrough depicting basic NoSQL injections on MongoDB.
  • XXE Injection — Exploiting XML External Entities.
  • Server-side Template Injection — Exploit various templating engines that lead to SSTI vulnerability.
  • LDAP Injection — Exploiting Lightweight Directory Access Protocol.
  • ORM Injection — Learn how to exploit injection vulnerabilities in an ORM-based web app.
  • Injectics — Use your injection skills to take control of a web app.
3
Network Security + Advanced Server-Side Attacks
Hours: 18 hours
$1,058.96 USD/mo

Master the skills of advanced server-side attacks, covering SSRF, File Inclusions, Deserialization, Race Conditions, and Prototype Pollution.

  • Passive Reconnaissance
  • Active Reconnaissance
  • Nmap Live Host Discovery
  • Nmap Basic Port Scans
  • Nmap Advanced Port Scans
  • Nmap Post Port Scans
  • Protocols and Servers
  • Protocols and Servers 2
  • Net Sec Challenge
  • Insecure Deserialisation — Get in-depth knowledge of the deserialisation process and how it poses a vulnerability in a web app.
  • SSRF — Discover the inner workings of SSRF and explore multiple exploitation techniques.
  • File Inclusion, Path Traversal — Exploit File Inclusion and Path Traversal vulnerabilities.
  • Race Conditions — Learn about race conditions and how they affect web application security.
  • Prototype Pollution — Explore the concept of prototype pollution and its implications during pentesting.
  • Include — Use your server exploitation skills to take control of a web app.
4
Vulnerability Research
Hours: 4 hours
$257.58 USD/mo
  • Vulnerabilities 101
  • Exploit Vulnerabilities
  • Vulnerability Capstone
5
Metasploit
Hours: 4 hours
$257.58 USD/mo
  • Metasploit: Introduction
  • Metasploit: Exploitation
  • Metasploit: Meterpreter
6
Privilege Escalation + Advanced Client-Side Attacks + HTTP Request Smuggling
Hours: 48 hours
$2,032.05 USD/mo

Through real-world scenarios, you will gain a detailed understanding of client-side attacks, including XSS, CSRF, DOM-based vectors, SOP, and CORS vulnerabilities. Learn to identify and exploit HTTP request smuggling, covering CL.TE, TE.CL, transfer-encoding obfuscation, browser desync, and HTTP2 smuggling.

  • What the Shell?
  • Linux Privilege Escalation
  • Windows Privilege Escalation
  • XSS — Explore in-depth the different types of XSS and their root causes.
  • CSRF — Learn how a CSRF vulnerability works and methods to exploit and defend against CSRF vulnerabilities.
  • DOM-Based Attacks — Learn about DOM-based vulnerabilities that can be leveraged to stage client-side attacks!
  • CORS & SOP — Cross-Origin Resource Sharing and Same-Origin Policy.
  • Whats Your Name? — Utilise your client-side exploitation skills to take control of a web app.
  • HTTP Request Smuggling — Learn about HTTP Request Smuggling and its different techniques.
  • HTTP/2 Request Smuggling — Exploit HTTP Request Smuggling in HTTP/2 environments.
  • Request Smuggling: WebSockets — Exploit HTTP Request Smuggling through WebSockets.
  • HTTP Browser Desync — Learn about Request Smuggling Browser Desync.
  • El Bandito — Can you help capture El Bandito before he leaves the galaxy?

Includes Lab for a month. All prices are monthly (MXN), before taxes.

Plan your training path

Tell us your team, schedule and modules of interest and we will reply with the next steps.

Request information

Online enrollment is coming soon. In the meantime, contact us to enroll.