Skip to content
Cyber Courses
Tous les métiers

Junior

Web Application Penetration Tester

Web pentesters assess web applications and APIs for an organisation and report the business risk with real evidence. This path takes you from the mechanics of HTTP to exploiting and chaining the vulnerabilities that matter on a real engagement.

Compétences requises

Les compétences clés de ce métier. Chacune regroupe les prérequis dont elle dépend.

Web fundamentals

  • Use HTTP request headers

    Comprend

    • Make HTTP requests

Access control

  • Exploit an IDOR

    Comprend

    • Make HTTP requests
    • Read from a REST API

SQL injection

  • Exploit UNION-based SQL injection

    Comprend

    • Make HTTP requests
    • Write SQL queries
    • Detect SQL injection
    • Exploit SQL injection

Cross-site scripting

  • Exploit cross-site scripting

    Comprend

    • Make HTTP requests
    • Detect cross-site scripting

Votre parcours

Les leçons qui comblent vos écarts, dans l'ordre. Les compétences maîtrisées sont ignorées.

  1. 1Anatomy of an HTTP requestWeb foundations for security · Make HTTP requests Commencer
  2. 2Headers and authenticated requestsWeb foundations for security · Use HTTP request headers, Read from a REST API Commencer

En quoi consiste le métier

  • Map an application's attack surface and how it handles requests.
  • Find and exploit injection, access-control and client-side flaws.
  • Prove impact with real evidence, not a scanner's guess.
  • Write findings a developer can act on.