Study any time, from any device.

Learn Web Application Pentesting

The Web Application Pentesting skill path teaches you how to discover and exploit vulnerabilities in Web apps. You'll learn how to use popular penetration testing tools to perform an analysis of Web applications, assess their weaknesses and better defend them from malicious attacks.

5 courses  //   23 videos  //   3 hours of training

Web Application Pentesting training

This learning path focuses on building your Web application penetration testing skills. As you progress through five courses, you’ll learn about gaining access to Web apps by attacking session management and bypassing client-side controls, gathering intelligence and mapping applications for attack, sneaking malicious code into applications, and leveraging other methods and tools used by hackers. Upon completion, you’ll have the knowledge and skills necessary to successfully carry out a penetration test against Web applications.

Learning path components


What you’ll learn.

  • Web app pentesting methodologies
  • Exploiting Web app access controls
  • Gathering information on Web apps
  • SQL and code injection attacks
  • Other popular attacks, such as clickjacking and cross-site scripting
  • And more!

Who is this for?

A familiarity of penetesting concepts and a Security+ certification, or equivalent knowledge, are recommended.

This skill path is designed for:

  • Penetration testers
  • Cybersecurity consultants
  • Web application developers
  • Web administrators
  • Anyone with a desire to improve their Web application pentesting skills!

You're in good company

"Comparing Infosec to other vendors is like comparing apples to oranges. My instructor was hands-down the best I’ve had." 

James Coyle

FireEye, Inc.

"I knew Infosec could tell me what to expect on the exam and what topics to focus on most."

Julian Tang

Chief Information Officer

"I’ve taken five boot camps with Infosec and all my instructors have been great."

Jeffrey Coa

Information Security Systems Officer