Junior
Web Application Penetration Tester
Web pentesters assess web applications and APIs for an organisation and report the business risk with real evidence. This path takes you from the mechanics of HTTP to exploiting and chaining the vulnerabilities that matter on a real engagement.
Skills this role needs
The capstone skills for this role. Each folds in the prerequisites it depends on.
Web fundamentals
- Use HTTP request headers
Includes
- Make HTTP requests
Access control
- Exploit an IDOR
Includes
- Make HTTP requests
- Read from a REST API
SQL injection
- Exploit UNION-based SQL injection
Includes
- Make HTTP requests
- Write SQL queries
- Detect SQL injection
- Exploit SQL injection
Cross-site scripting
- Exploit cross-site scripting
Includes
- Make HTTP requests
- Detect cross-site scripting
Your path
The lessons that close your gaps, in order. Mastered skills are skipped.
What the job involves
- Map an application's attack surface and how it handles requests.
- Find and exploit injection, access-control and client-side flaws.
- Prove impact with real evidence, not a scanner's guess.
- Write findings a developer can act on.