We use cookies to ensure you get the best user experience. For more information see our cookie policy.

TryHackMe logo.
  • Learn

  • AI Upskilling

  • Education

  • Pricing

TryHackMe logo.
Join for FREE
Back to all modules

Web Frameworks

Web Frameworks icon

Learn how to read a framework's source code like an attacker and exploit the bugs it ships by default.

This module covers white-box web application testing: tracing a vulnerability from source code to a working exploit across the frameworks that carry most production traffic. Learners start with the review method itself, reading code, mapping attack surface, and grepping for dangerous patterns, before applying it stack by stack. Spring Boot brings Actuator misconfiguration, SQL injection below the ORM, mass assignment, and deserialisation. Django and Flask bring debug exposure, session forgery, and template injection. ASP.NET brings ViewState tampering, mass assignment, and deserialisation. Each framework room ends with a practical task chaining that stack's bugs into one exploit path, and a hard capstone challenge closes the module by combining four Spring Boot flaws in a single unredacted codebase to reach remote code execution.

Web Frameworks icon

0%

Web Frameworks: Code Review

walkthrough

Read web app source like an attacker: trace user input to dangerous sinks, triage with Semgrep.

0%

Web Frameworks: Java

walkthrough

Review Spring Boot source, find the framework-specific sinks, and exploit each on the lab machine.

0%

Web Frameworks: Python

walkthrough

Review Django and Flask source for framework-specific sinks, then exploit each on the lab machine.

0%

Web Frameworks: .NET

walkthrough

Review ASP.NET source, find the framework-specific sinks, and exploit each on the lab machine.

0%

Source Code Review: PHP

walkthrough

Learn the basics of source code review for PHP.

Topic Rewind Recap

Lock in what you learned with a recap. Earn points and keep your streak.

Need to know

Need to know: Chaining Vulnerabilities

Chaining Vulnerabilities

Learn how to chain multiple vulnerabilities to compromise a system and test your chaining skills through advanced real-world challenges.

Next steps

Next steps: Advanced Server-Side Attacks

Advanced Server-Side Attacks

Master the skills of advanced server-side attacks, covering SSRF, File Inclusions, Deserialization, Race Conditions, and Prototype Pollution.

What are modules?

A learning pathway is made up of modules, and a module is made of bite-sized rooms (think of a room like a mini security lab).

Hierarchical diagram showing how learning pathways contain modules, which contain individual rooms.

Learning

  • Hands-on labs
  • For Business
  • For Education
  • Competitive Hacking
  • Certifications

Resources

  • About Us
  • Newsroom
  • Blog
  • Glossary
  • Work at TryHackMe
  • Careers in Cyber

Privacy & Legal

  • Privacy Policy
  • Terms of Use
  • AI Terms of Use
  • Acceptable Use Policy
  • Cookie Policy

Get in touch

  • Contact Us
  • Affiliates
  • Student Discount

Shop

  • Swag Shop

We're a gamified, hands-on cyber security training platform that you can access through your browser.

128 City Road, London, United Kingdom, EC1V 2NX

Copyright TryHackMe 2018-2026

ISO27001 Compliant