Cybersecurity

Web Application Security

Practical learning resources covering web application vulnerabilities, exploitation techniques, detection methodologies, secure development and production-grade remediation.

Category overview

6

Topics

39

Lessons

Learning topics

Explore Web Application Security

Choose a topic and start building your security skills.

6 topics

SQL Injection

Server-Side

A comprehensive study of SQL injection vulnerabilities, exploitation techniques, detection, impact, testing methodology, and production-grade prevention.

4 lessons
Start learning

Cross-Site Scripting (XSS)

Client-Side

Cross-Site Scripting (XSS) is a client-side injection vulnerability where an attacker gets their own script to run inside another user's browser, in the security context of a website that user already trusts.

5 lessons
Start learning

Authentication Vulnerabilities

Both

Authentication vulnerabilities are weaknesses that allow an attacker to access an account or protected resource without properly proving that they are the legitimate user.

8 lessons
Start learning

Authorization and Access Control

Server-Side

Authorization determines what an authenticated user is allowed to access or perform. Access control ensures these permissions are enforced so users cannot access resources or functionality beyond their assigned privileges.

7 lessons
Start learning

Session Management

Server-Side

Session management vulnerabilities occur when an application incorrectly creates, stores, transmits, validates, or invalidates authenticated sessions.

9 lessons
Start learning

Cross Site Request Forgery

Server-Side

CSRF is a server-side vulnerability in which an attacker causes a victim's browser to send a malicious or unintended request to the target application where the victim is authenticated. If the server does not have adequate CSRF protection, it may execute the malicious request and treat it as a legitimate request from the authenticated user.

6 lessons
Start learning