An advanced web application security review course. Will teach the skills needed to
conduct white box web app penetration tests.

After completing this course, Analyst will be able to understand:

  1. Tools & Methodologies
  2. ATutor Authentication Bypass and RCE
  3. ATutor LMS Type Juggling Vulnerability
  4. ManageEngine Applications Manager AMUserResourcesSyncServlet SQL
    Injection RCE
  5. Bassmaster NodeJS Arbitrary JavaScript Injection Vulnerability
  6. DotNetNuke Cookie Deserialization RCE
  7. ERPNext Authentication Bypass and Server Side Template Injection
  8. openCRX Authentication Bypass and Remote Code Execution
  9. openITCOCKPIT XSS and OS Command Injection – Blackbox
  10. Concord Authentication Bypass to RCE
  11. Server-Side Request Forgery
  12. Guacamole Lite Prototype Pollution
  13. Conclusion
  14. Atmail Mail Server Appliance: from XSS to RCE archived.