0%
Walking An Application
Manually review a web application for security issues using only your browser's developer tools.
0%
Content Discovery
Discover hidden web content using manual techniques, OSINT, and Gobuster enumeration.
0%
Modern Web Stacks
Four web stacks, four CVEs: fingerprint MERN, Next.js, Django, and LAMP, then exploit each one.
0%
Web Server Attacks - I
Enumerate and identify misconfigurations across Apache, Nginx, Node.js, and Python HTTP Server.
0%
Web Server Attacks - II
Attack IIS through fingerprinting, tilde enumeration, WebDAV shell upload, and learn automation.
Topic Rewind Recap
Lock in what you learned with a recap. Earn points and keep your streak.
Map how modern web applications are built, uncover their hidden endpoints, and exploit the most common web server weaknesses.
This module opens your web application testing journey by teaching you to walk through a target the way an attacker does, surfacing the hidden pages, directories, and files that ordinary users never see. You’ll then dig into the modern stacks that power today’s sites, understanding how frontend frameworks, APIs, and backend technologies each introduce their own attack surface. By the end, you’ll be running practical web server attacks and reading them through a pentester’s lens.
What are modules?
A learning pathway is made up of modules, and a module is made of bite-sized rooms (think of a room like a mini security lab).

