Home / Training / Certified Web Application Security Pentester

Certified Web Application Security Pentester

Master penetration testing and web application security auditing.

Objective

A penetration test evaluates an infrastructure’s security by safely exploiting vulnerabilities that may exist in operating systems, application errors, or user behavior. The penetration test aims to assess the effectiveness of security measures and uncover any potential exploits or backdoors that might be present in computer systems, which cybercriminals could use to gain unauthorized access or conduct malicious activities.

Specific Objectives:

  • Identify and analyze the organization’s exposure to cybersecurity threats
  • Enhance your foundational cybersecurity auditing skills

Prerequisites

  • Identify vulnerabilities and successfully execute attacks
  • Perform information security roles responsibly

General Information

  • Code: C-WAST
  • Duration: 3 days
  • Schedule: 8:30 AM - 5:30 PM
  • Location: 4-star hotel, Tunis

Target Audience

  • System and Network Administrators
  • Security Auditor/Technician
  • Chief Information Security Officer (CISO)

Resources

  • Course materials
  • 40% demonstration
  • 40% theory
  • 20% practical exercises

Training Program

  • Introduction to penetration testing
  • Basic Windows commands
  • Basic Linux commands
  • Bypassing login via SQL injection
  • SQL Injection chain, sqlmap
  • Blind SQL Injection, Python script
  • Executing netcat command, commix
  • Password attack methods to obtain credentials. Tools: Hydra, Python Script, BurpSuite.
  • POST method password attack. Tools: Hydra, Python Script, BurpSuite.
  • HTTP verb tampering. Tools: Live http Header, Firefox add-on, curl.
  • Redirection and unvalidated transfers. Tools: NoRedirect, Firefox add-on, curl.
  • Upload
  • Filtered Upload. Tools: Fuzzing data
  • PHP bulk comparison. Tools: Qcunetix, Dirb, Tamper Data; Firefox Addon.
  • Time Attack
  • XSS Reflected
  • Stored XSS, tool: XWotP Xenotix OWASP exploit framework
  • Filtered Stored XSS, tool: BurpSuite
  • LFI
  • RFI, tools: Apache, fimap
  • CSRF Attack
  • Exam preparation
  • The exam will be held in a 4-star hotel located in Tunis.
  • Exam title: ECSAv10
  • Exam format: Multiple-choice questions (MCQ) and LAB on machine
  • Number of questions: 30 MCQ
  • Duration: 1 hour for MCQ, 1 hour for LAB
  • Language: French
  • Passing score: 60%

Don't hesitate to contact our experts for additional information, free audit studies, and cost estimates.

Information security is essential for any organization that needs to protect and enhance its information assets.

Contact Us