Web security training is our passion. We’ve trained over 100 current cybersecurity professionals, including associates of top-tier firms and companies within the fortune 500. We’ve also trained two Drexel Cyberdragons presidents which went on to win 1st in the CCDC.

We offer a cybersecurity boot camp which prepares students for a career in cybersecurity. Students learn a wealth of hacking techniques to compromise web applications and practice exploiting the vulnerabilities manually in a lab environment using Burp Suite.

Web Security Topics:

  • SQL Injection (SQLi)
  • Cross-Site Scripting (XSS)
  • Local /Remote File Inclusion (LFI/RFI)
  • XML External Entity Injection (XXE)
  • Insecure Direct Object Reference (IDOR / Forceful Browsing)
  • Unrestricted File Upload (UFU)
  • Unvalidated Redirects
  • Cross-Site Request Forgery (CSRF)
  • Command Injection
  • Password Reset Weaknesses

Advanced Web Security Topics (1 Day Remote)

  • SQL Injection Masterclass
  • Cross-Site Scripting Masterclass
  • Unsafe Deserialization
  • Breaking Crypto in Web Apps
    • Hash Length Extension Attack
    • ECB
    • Padding Oracles