Skip to content
Cyber Courses
All roles

Junior

Web Application Penetration Tester

Web pentesters assess web applications and APIs for an organisation and report the business risk with real evidence. This path takes you from the mechanics of HTTP to exploiting and chaining the vulnerabilities that matter on a real engagement.

Skills this role needs

The capstone skills for this role. Each folds in the prerequisites it depends on.

Web fundamentals

  • Use HTTP request headers

    Includes

    • Make HTTP requests

Access control

  • Exploit an IDOR

    Includes

    • Make HTTP requests
    • Read from a REST API

SQL injection

  • Exploit UNION-based SQL injection

    Includes

    • Make HTTP requests
    • Write SQL queries
    • Detect SQL injection
    • Exploit SQL injection

Cross-site scripting

  • Exploit cross-site scripting

    Includes

    • Make HTTP requests
    • Detect cross-site scripting

Your path

The lessons that close your gaps, in order. Mastered skills are skipped.

  1. 1Anatomy of an HTTP requestWeb foundations for security · Make HTTP requests Start
  2. 2Headers and authenticated requestsWeb foundations for security · Use HTTP request headers, Read from a REST API Start

What the job involves

  • Map an application's attack surface and how it handles requests.
  • Find and exploit injection, access-control and client-side flaws.
  • Prove impact with real evidence, not a scanner's guess.
  • Write findings a developer can act on.