Skip to main content

Map how modern web applications are built, uncover their hidden endpoints, and exploit the most common web server weaknesses.

This module opens your web application testing journey by teaching you to walk through a target the way an attacker does, surfacing the hidden pages, directories, and files that ordinary users never see. You’ll then dig into the modern stacks that power today’s sites, understanding how frontend frameworks, APIs, and backend technologies each introduce their own attack surface. By the end, you’ll be running practical web server attacks and reading them through a pentester’s lens.

What are modules?

A learning pathway is made up of modules, and a module is made of bite-sized rooms (think of a room like a mini security lab).

Hierarchical diagram showing how learning pathways contain modules, which contain individual rooms.