Web Application Penetration Testing Online

While some security courses may brush over application security, or cover the security of small-scale “demo” applications, InfoSec Institute concentrates on the latest attacks against modern web applications.

or call us on (866)-471-0059

Course Overview

InfoSec Institute's award winning Web Application Penetration Testing Boot Camp focuses on preparing students for the real world of Web App Pen Testing through extensive lab exercises thought provoking lectures led by an expert instructor. We review of the entire body of knowledge as it pertains to web application pen testing through a high-energy seminar approach.

InfoSec Institute offers this award winning Web Application Penetration Testing program to train and prepare IT Security Professionals.

The highlights of this course include:

Intensive Hands-On Training:

The Web Application Penetration Testing course from InfoSec Institute is a totally hands-on learning experience. From the first day to the last day, you will learn the ins and outs of Web App Pen Testing by attending thought provoking lectures led by an expert instructor. Every lecture is directly followed up by a comprehensive lab exercise (we also set up and provide lab workstations so you don't waste valuable class time installing tools and apps).

Typical lab exercises consist of a real-world app that demonstrates a vulnerability commonly found in a web app. You learn how to assess the app much as a black hat hacker would, exploit the app so that you can demonstrate the true risk of the vulnerability to the application owner. This can involve taking control of the application itself, downloading data the application stores, or potentially using the app as a launching pad to attack unsuspecting visitors with a malicious script. Finally, the lab will follow up with remediation steps so that the application owner can properly close down the security hole for good.

Up To Date, Current, Courseware

The threat landscape for Web Applications changes on a near continuous basis. Bad guys wishing to attack your applications know that they need to stay ahead of the curve in order to get in. For this reason, InfoSec Institute continuously updates our Web App Pen Testing courseware to cover the latest and greats threats, exploits and mitigation strategies.

Expert Instruction

InfoSec Institute instructors that teach the Web App Pen Testing course are highly seasoned and have years of in the field pen testing experience. Not only are they active in the field of pen testing, they are industry-recognized experts that present at conferences such as DEFCON, Black Hat Briefings, RSA Security. Many of our instructors have authored some of the top Penetration Testing books on the market today.

This hands-on course teaches you:

  1. The fundamentals of modern Application Security on both .Net and Java platforms
  2. Application security threats and assessment/attack techniques
  3. The latest threats to Web Services and AJAX-enabled applications

View Pricing

We will never share any of your information, spam you or annoy you with pushy sales pitches.

View Price Now

Web App Topics & Labs

InfoSec Institute has only the highest quality instructors, with deep background in Application Security. Our instructors are actively involved in the Application Security community. They have authored several books on the subject, spoken at various industry conferences, and are considered subject matter experts. 

  • Secure Programming Throughout the Application Development Lifecycle
  • Confronting Flawed Input Data
  • Implementation Best Practices
  • Source code analysis scanning software
  • Code Origin Access Control Methods
  • Network Transmission Security with the JSSE API/SSL
  • WS Security, XKMS, and WS-I Basic security profile
  • SecureXML Libraries
  • Privilege Escalation Opportunities
  • Race Conditions
  • Cross Site Scripting Injection
  • .Net Secure Remoting
  • Windows Forms Security
  • SQL Server: Exploitation and Defense
  • Fault Injection and Fuzzing
  • Java security managers, policy files, and JAAS
  • ASP.NET Security
  • XOR, Base64 and Garbage Data Obfuscation
  • Securely Maintaining Session State – Best Practices
  • Session fixation
  • Advanced SQL Injection
  • Oracle PL/SQL Injection
  • .Net Security tokens, XML signature, XML canonicalization, and XML encryption
  • Net WS-Trust and WS-Secure Conversation
  • Error Control Verbosity Abuse

Interested in training?

You can register your interest and we’ll keep you up to date when public courses become available. You can also register your interest in on-site training.

Thanks! We’ll keep you updated
As soon as we have news of the status of this course, we’ll be in touch.
  • or call us on (866)-471-0059

We’ve trained over 50,000 happy people

Web Application Penetration Testing Online is part of these career tracks

New Exam Pass Guarantee!

Our new Live Online format has produced excellent results. We trust the course quality will help you pass on your first exam attempt and this exam-pass guarantee backs up that trust.