Web Penetration Testing Course - Master Application Security
Master web penetration testing with our dynamic training program. Learn to exploit vulnerabilities using cutting-edge techniques and tools like BurpSuite Pro and sqlmap. Gain expertise in HTTP protocols, SSL weaknesses, file-related vulnerabilities, injection attacks including SQLi/XXE, CSRF defense tactics, logic flaws analysis and more.
- Available in:
- Malaysia
Corporate Pricing
Pax:
Training Provider Pricing
Pax:
Features
Target Audience
Methodologies
Subsidies

What you'll learn
- Develop proficiency in scripting for automation during penetration tests.
- Execute sophisticated injection attacks such as SQLi/XXE.
- Understand the basics of HTTP protocols and web application architectures.
- Identify and exploit various file-related vulnerabilities including LFI/RFI.
- Navigate complex authentication mechanisms and session management vulnerabilities.
- Conduct effective information gathering using OSINT and other reconnaissance methods.
- Implement CSRF mitigation strategies and understand logic flaw exploitation.
- Utilize advanced penetration testing tools including Nmap, WPScan, Metasploit.
Why should you attend?
Web Penetration Testing is an essential skill set for security professionals seeking to identify and exploit vulnerabilities within web applications. This comprehensive course delves into the intricacies of various web technologies, equipping participants with a deep understanding of the HTTP protocol, encoding schemes, and state management mechanisms. Participants will explore the OWASP Top 10, CWE, and SANS 25 to comprehend the most critical web security risks. The course progresses by covering information gathering techniques using WHOIS, DNS reconnaissance, and open source intelligence (OSINT). It also addresses SSL configurations and interception proxies like BurpSuite Pro and Zed Attack Proxy. Learners will engage in content discovery, session testing, authentication bypasses, and utilize tools like fuff and Mutillidae to brute force unlinked files and directories. File-related vulnerabilities such as Local File Inclusion (LFI), Remote File Inclusion (RFI), unrestricted file uploads, and remote code execution are thoroughly examined. Injection attacks including SQL injection, command injection, directory traversal, insecure deserialization, and XML External Entity (XXE) exploitation form a core component of this curriculum. Moreover, learners will gain insights into advanced attack vectors like Cross-Site Request Forgery (CSRF), logic flaws, API attacks, AJAX security issues, and the use of Python for penetration testing. Finally, the course covers the effective use of industry-standard tools such as Nmap, WPScan, Metasploit, BurpSuite Pro Scanner, along with strategies for website auditing and post-assessment reporting.
Course Syllabus
Day 1 - Web Application Fundamentals
Short Break
15 minsRecap and Q&A
15 minsLunch
1 hourShort Break
15 minsRecap and Q&A
15 minsEnd of Day 1
Day 2 - Information Gathering Techniques
Short Break
15 minsRecap and Q&A
15 minsLunch
1 hourShort Break
15 minsRecap and Q&A
15 minsEnd of Day 2
Ratings and Reviews
Instructor
Dr. Esther Suria Kala is a highly accomplished ICT consultant and corporate trainer with nearly 30 years of extensive experience in information technology, project management, and organizational development. As the founder of Angel Software Solutions, she has established herself as a versatile and dedicated professional who delivers cutting-edge training solutions across Malaysia and internationally.
Her academic credentials are exceptional, including a PhD in Psychology with a focus on Human Behaviour and Human Resources, an MBA in Finance, and degrees in both Computer Science and Human Resources. Currently pursuing a second PhD in IT Information Security, Dr. Esther demonstrates an unwavering commitment to continuous learning and staying at the forefront of technological advancement. Her educational foundation is complemented by an impressive array of professional certifications, including Microsoft Certified Trainer (MCT), CISSP, ITIL, SAP Certified Associate, Certified Cyber Security Professional, Data Scientist, AI Engineering, and ECBA certifications.
Dr. Esther's technical expertise spans an extensive range of domains, from traditional programming languages like Java, C++, and PHP to modern technologies including Python, AI coding, machine learning, RPA, and IR 4.0 microservices. She is proficient in database management systems including Microsoft SQL Server and Oracle, web development frameworks, and enterprise solutions like SAP Crystal Reports and SharePoint Server. Her knowledge extends to cybersecurity, ethical hacking, network administration, and data analytics, making her uniquely qualified to address both technical and strategic business challenges.
As a trainer, Dr. Esther excels in bridging the gap between technical complexity and practical application. She delivers comprehensive training programs for both IT and non-IT professionals, covering everything from software development and cloud computing to soft skills such as digital marketing, business analysis, customer service, and project management. Her ability to communicate effectively in both English and Bahasa Malaysia enables her to connect with diverse audiences across different organizational levels.
Her impressive client portfolio includes leading organizations such as Maybank, Telekom Malaysia, Malaysian Airlines, Tenaga Nasional Berhad, Bank Negara, Ministry of Education, Ministry of Finance, and numerous multinational corporations. This extensive experience across banking, telecommunications, government, aviation, and technology sectors demonstrates her adaptability and deep understanding of varied industry requirements. Recognized with the Outstanding Achievement Award in Information Technology from University Malaya in 2013, Dr. Esther continues to empower organizations through innovative training solutions that drive digital transformation and professional excellence.
Instructor
Course Reviews
"Great course. I was able to gain knowledge on web application security and how to identify and prevent common vulnerabilities."
"Best course material to develop expertise in using advanced tools such as BurpSuite Pro scanner and Metasploit."
"I like the course. It provided me with the immense knowledge."
FAQ
Frequently Asked Questions About This Course
- Public pricing: applies for individuals signing up from different companies.
- Corporate pricing: applies if a company wants to have an intake for its employees only.
- Training provider pricing: applies only for other training providers looking to hire our trainers and use our content. Our content has a licensing fee.
We will keep you updated on the status of the intake after you enroll.
Courses you may like
Why should you attend?
Web Penetration Testing is an essential skill set for security professionals seeking to identify and exploit vulnerabilities within web applications. This comprehensive course delves into the intricacies of various web technologies, equipping participants with a deep understanding of the HTTP protocol, encoding schemes, and state management mechanisms. Participants will explore the OWASP Top 10, CWE, and SANS 25 to comprehend the most critical web security risks. The course progresses by covering information gathering techniques using WHOIS, DNS reconnaissance, and open source intelligence (OSINT). It also addresses SSL configurations and interception proxies like BurpSuite Pro and Zed Attack Proxy. Learners will engage in content discovery, session testing, authentication bypasses, and utilize tools like fuff and Mutillidae to brute force unlinked files and directories. File-related vulnerabilities such as Local File Inclusion (LFI), Remote File Inclusion (RFI), unrestricted file uploads, and remote code execution are thoroughly examined. Injection attacks including SQL injection, command injection, directory traversal, insecure deserialization, and XML External Entity (XXE) exploitation form a core component of this curriculum. Moreover, learners will gain insights into advanced attack vectors like Cross-Site Request Forgery (CSRF), logic flaws, API attacks, AJAX security issues, and the use of Python for penetration testing. Finally, the course covers the effective use of industry-standard tools such as Nmap, WPScan, Metasploit, BurpSuite Pro Scanner, along with strategies for website auditing and post-assessment reporting.
What you'll learn
- Develop proficiency in scripting for automation during penetration tests.
- Execute sophisticated injection attacks such as SQLi/XXE.
- Understand the basics of HTTP protocols and web application architectures.
- Identify and exploit various file-related vulnerabilities including LFI/RFI.
- Navigate complex authentication mechanisms and session management vulnerabilities.
- Conduct effective information gathering using OSINT and other reconnaissance methods.
- Implement CSRF mitigation strategies and understand logic flaw exploitation.
- Utilize advanced penetration testing tools including Nmap, WPScan, Metasploit.
Course Syllabus
Day 1 - Web Application Fundamentals
Short Break
15 minsRecap and Q&A
15 minsLunch
1 hourShort Break
15 minsRecap and Q&A
15 minsEnd of Day 1
Day 2 - Information Gathering Techniques
Short Break
15 minsRecap and Q&A
15 minsLunch
1 hourShort Break
15 minsRecap and Q&A
15 minsEnd of Day 2
Course Reviews
"Great course. I was able to gain knowledge on web application security and how to identify and prevent common vulnerabilities."
"Best course material to develop expertise in using advanced tools such as BurpSuite Pro scanner and Metasploit."
"I like the course. It provided me with the immense knowledge."
Corporate Pricing
Pax:
Training Provider Pricing
Pax:
Features
Target Audience
Methodologies
Subsidies

Ratings and Reviews
Instructors
Dr. Esther Suria Kala is a highly accomplished ICT consultant and corporate trainer with nearly 30 years of extensive experience in information technology, project management, and organizational development. As the founder of Angel Software Solutions, she has established herself as a versatile and dedicated professional who delivers cutting-edge training solutions across Malaysia and internationally.
Her academic credentials are exceptional, including a PhD in Psychology with a focus on Human Behaviour and Human Resources, an MBA in Finance, and degrees in both Computer Science and Human Resources. Currently pursuing a second PhD in IT Information Security, Dr. Esther demonstrates an unwavering commitment to continuous learning and staying at the forefront of technological advancement. Her educational foundation is complemented by an impressive array of professional certifications, including Microsoft Certified Trainer (MCT), CISSP, ITIL, SAP Certified Associate, Certified Cyber Security Professional, Data Scientist, AI Engineering, and ECBA certifications.
Dr. Esther's technical expertise spans an extensive range of domains, from traditional programming languages like Java, C++, and PHP to modern technologies including Python, AI coding, machine learning, RPA, and IR 4.0 microservices. She is proficient in database management systems including Microsoft SQL Server and Oracle, web development frameworks, and enterprise solutions like SAP Crystal Reports and SharePoint Server. Her knowledge extends to cybersecurity, ethical hacking, network administration, and data analytics, making her uniquely qualified to address both technical and strategic business challenges.
As a trainer, Dr. Esther excels in bridging the gap between technical complexity and practical application. She delivers comprehensive training programs for both IT and non-IT professionals, covering everything from software development and cloud computing to soft skills such as digital marketing, business analysis, customer service, and project management. Her ability to communicate effectively in both English and Bahasa Malaysia enables her to connect with diverse audiences across different organizational levels.
Her impressive client portfolio includes leading organizations such as Maybank, Telekom Malaysia, Malaysian Airlines, Tenaga Nasional Berhad, Bank Negara, Ministry of Education, Ministry of Finance, and numerous multinational corporations. This extensive experience across banking, telecommunications, government, aviation, and technology sectors demonstrates her adaptability and deep understanding of varied industry requirements. Recognized with the Outstanding Achievement Award in Information Technology from University Malaya in 2013, Dr. Esther continues to empower organizations through innovative training solutions that drive digital transformation and professional excellence.
Courses you may like
FAQ
Frequently Asked Questions About This Course
- Public pricing: applies for individuals signing up from different companies.
- Corporate pricing: applies if a company wants to have an intake for its employees only.
- Training provider pricing: applies only for other training providers looking to hire our trainers and use our content. Our content has a licensing fee.
We will keep you updated on the status of the intake after you enroll.
Our Offers
Academy for Trainers Academy for Trainers
Teach what you love. Abundent Academy gives you the tools you need to run your own trainings! We provide you with the platform, the students, the materials, and the support you need to succeed!
- Higher trainer payouts
- Ready-made course materials
- Student management system
- AI digital marketing assistant
Academy for Corporates Academy for Corporates
Get unlimited access to all of Abundent Academy's carefully curated courses for your team, all organized according to learning paths and roles! Perfect for companies looking to upskill their workforce and stay ahead in the tech industry.
- Carefully curated courses
- Role-based learning paths
- Team progress tracking
- Gap Identification and Analysis
Academy for Partners Academy for Partners
White-label IT training delivery for training providers. We become your behind-the-scenes delivery arm so you can say yes to more clients without hiring more trainers.
- Expand your training catalog
- 40+ expert trainers ready
- White-label delivery
- You keep client relationships