Junior
Web Application Penetration Tester
Web pentesters assess web applications and APIs for an organisation and report the business risk with real evidence. This path takes you from the mechanics of HTTP to exploiting and chaining the vulnerabilities that matter on a real engagement.
Compétences requises
Les compétences clés de ce métier. Chacune regroupe les prérequis dont elle dépend.
Web fundamentals
- Use HTTP request headers
Comprend
- Make HTTP requests
Access control
- Exploit an IDOR
Comprend
- Make HTTP requests
- Read from a REST API
SQL injection
- Exploit UNION-based SQL injection
Comprend
- Make HTTP requests
- Write SQL queries
- Detect SQL injection
- Exploit SQL injection
Cross-site scripting
- Exploit cross-site scripting
Comprend
- Make HTTP requests
- Detect cross-site scripting
Votre parcours
Les leçons qui comblent vos écarts, dans l'ordre. Les compétences maîtrisées sont ignorées.
En quoi consiste le métier
- Map an application's attack surface and how it handles requests.
- Find and exploit injection, access-control and client-side flaws.
- Prove impact with real evidence, not a scanner's guess.
- Write findings a developer can act on.