Security Operations · Beginner
Ethical Hacking and Web Security Foundations
Learn how common web attacks work by finding them on a deliberately vulnerable app in an isolated lab, then fix and detect each one. Authorization and ethics come first, always.
About this course
This is a hands-on, defence-first introduction to web application security. You work only inside a strictly isolated lab: an attacker workstation (`attacker01`) and one deliberately vulnerable teaching application (`target01`) on a private network with no route to the internet. Nothing you do here ever touches a real site, a third party, or a system you were not explicitly authorized to test. Every technique is taught for one reason: you cannot reliably defend what you do not understand. For each vulnerability class — SQL injection, cross-site scripting, broken authentication and session management, broken access control, and security misconfiguration — you will see how an attacker finds and exploits it, and then, in the same lesson, exactly how to fix it and how to spot it in logs. Finding, fixing, and detecting are treated as one skill, not three. You will use the standard teaching toolset — a browser and its developer tools, `curl`, `nmap` (against your lab target only), and open, well-documented techniques — and you will practise the professional habits that separate a security practitioner from an intruder: agreeing scope in writing, staying inside it, writing a clear vulnerability report, and disclosing responsibly. The course closes with an authorized assessment of the teaching app that mirrors real junior-analyst work. This course is a learning pathway toward defensive web-security work. It does not promise a job, a salary, or a vendor credential; on completion you earn an Ultiblob Certificate of Completion.
- Content time
- 12 h
- Lessons
- 10
- Certificate
- Yes
- on completion
Lesson 1 is free. Enroll in a career path to access its full courses.
Lesson 1 is a free preview — read it without an account.

Outline
Lessons
Lesson 1: Authorization, scope, and ethicsFree preview
The rules that make security testing legal and professional — and why this is a defensive skill.
55 minLesson 2: How the web works for attackers and defenders
HTTP requests and responses, headers, cookies, sessions, and TLS — read with curl and devtools.
1 hLesson 3: Reconnaissance in scope
Map one authorized target with nmap and endpoint discovery, and read what the app volunteers.
1 h 5 minLesson 4: Injection — SQL injection
How SQL injection works, find and exploit it on the teaching app, then fix it with parameterized queries.
1 h 30 minLesson 5: Cross-site scripting (XSS)
Reflected, stored, and DOM XSS — demonstrate it on the teaching app, then fix it with output encoding and CSP.
1 h 20 minLesson 6: Broken authentication and session management
Weak passwords, weak tokens, missing lockout, and unsafe cookies — and the flags and hashing that fix them.
1 h 15 minLesson 7: Access control failures
IDOR, path traversal, and privilege escalation on the teaching app — and the server-side checks that fix them.
1 h 20 minLesson 8: Security misconfiguration and sensitive data exposure
Missing headers, verbose errors, exposed endpoints and files — audited on target01 and mapped to the OWASP Top 10.
1 h 15 minLesson 9: From finding to fix to detection
Write a clear vulnerability report and learn how each attack appears in logs so it can be detected.
1 h 15 minLesson 10: Responsible disclosure and secure development habits
How to report vulnerabilities responsibly, model threats, and build security into the lifecycle — legally.
1 h 5 min
Where it leads