Choose your language
Website Hacking Course
Over 400,000 professionals on the platform
Exclusive for businesses

Website Hacking Course

Master the offensive techniques professional penetration testers use to break into real web applications. From SQL injection and XSS to SSRF and broken access control, this course covers every major vulnerability class in depth. You'll build a legal lab, exploit hands-on targets, and produce professional-grade reports that get results.

Dedika for students

What your team will master:

You'll learn how web applications are built and exactly where attackers find weaknesses in every layer. The course covers reconnaissance, scanning, injection attacks, authentication bypasses, cross-site scripting, and access control exploitation. You'll also tackle advanced topics like deserialisation, SSRF, vulnerability chaining, and cloud misconfigurations. Supplementary modules cover Burp Suite mastery, mobile and API security, secure code review, and bug bounty strategies. By the end, you'll know how to find, exploit, document, and remediate vulnerabilities across modern web environments.

How your team learns practically Website Hacking Course

How your team practises Website Hacking Course

Professionals from these companies study at Dedika

ActemiumFR
Nunner LogisticsNL
GT Constructora GeotécnicaCR
Sydel StarBR
Metrô de São PauloBR
Aguas AndinasCL
DSMIN
MeridianbetRS
CDHCN

Course content

8 Chapters • 36 LessonsDuration between 4 and 360 hours (you decide)

Chapter 1See details

Foundations of Web Security

  • Lesson 1 • Legal and Ethical Boundaries

    Defines authorised testing, responsible disclosure, and ethical obligations. Ensures students operate within professional and legal boundaries throughout the course.

  • Lesson 2 • Attacker Mindset and Methodology

    Introduces the offensive security mindset and structured attack phases. Frames all subsequent techniques within a repeatable, professional methodology.

  • Lesson 3 • Web Application Architecture

    Examines front-end, back-end, and database layers plus common frameworks. Connects architecture knowledge to identifying which layer a vulnerability lives in.

  • Lesson 4 • How Websites Work

    Covers HTTP/HTTPS request-response cycles, DNS resolution, and server roles. Establishes the technical baseline needed for every attack technique in the course.

  • Lesson 5 • Setting Up a Lab Environment

    Guides students through building an isolated, legal practice environment. Provides the hands-on infrastructure used in every subsequent chapter.

Chapter 2See details

Reconnaissance and Information Gathering

  • Lesson 1 • Passive Reconnaissance Techniques

    Covers OSINT methods that gather data without touching the target server. Feeds directly into attack planning by revealing infrastructure and personnel details.

  • Lesson 2 • Active Reconnaissance Techniques

    Teaches direct probing methods including port scanning and banner grabbing. Builds on passive findings to confirm live services and technology stacks.

  • Lesson 3 • DNS Enumeration

    Explores zone transfers, DNS brute-forcing, and record analysis. Expands the attack surface map by uncovering hidden subdomains and internal hostnames.

  • Lesson 4 • Technology Stack Fingerprinting

    Identifies CMS platforms, frameworks, and server software from HTTP headers and page artefacts. Narrows exploit selection to technologies confirmed on the target.

Chapter 3See details

Scanning and Vulnerability Assessment

  • Lesson 1 • Vulnerability Prioritisation and Reporting

    Applies severity scoring and business-impact analysis to rank findings. Prepares students to communicate risk clearly to technical and non-technical stakeholders.

  • Lesson 2 • OWASP Top 10 Overview

    Maps the most critical web vulnerability categories to real-world impact. Provides the classification framework used throughout the rest of the course.

  • Lesson 3 • Web Application Scanning Fundamentals

    Introduces automated scanners, their output formats, and false-positive management. Connects reconnaissance data to targeted scan configuration.

  • Lesson 4 • Manual Vulnerability Discovery

    Teaches proxy-based manual testing to find issues automated tools miss. Reinforces understanding of application logic as the foundation for later exploit chapters.

Chapter 4See details

Injection Attacks

  • Lesson 1 • Advanced SQL Injection Techniques

    Covers out-of-band exfiltration, stored procedures, and second-order injection. Extends basic skills to complex, real-world database configurations.

  • Lesson 2 • Command and Code Injection

    Demonstrates OS command injection and server-side code execution vulnerabilities. Connects injection concepts to server-level compromise beyond the database.

  • Lesson 3 • Injection Defence and Remediation

    Reviews parameterised queries, input validation, and least-privilege database accounts. Equips students to recommend concrete fixes after demonstrating injection impact.

  • Lesson 4 • NoSQL and XML Injection

    Targets MongoDB query operators and XML/XPath parsers with injection payloads. Broadens injection skills to non-relational and document-based data stores.

  • Lesson 5 • SQL Injection Fundamentals

    Explains how unsanitised input reaches SQL queries and how to craft payloads. Builds the conceptual foundation for all SQL injection variants covered next.

Chapter 5See details

Authentication and Session Attacks

  • Lesson 1 • Session Token Analysis and Hijacking

    Analyses token entropy, predictability, and transmission security to steal sessions. Builds on HTTP fundamentals to show how sessions can be captured or forged.

  • Lesson 2 • Credential-Based Attacks

    Covers brute-force, credential stuffing, and password spraying against login endpoints. Directly applies reconnaissance data to target real user accounts.

  • Lesson 3 • Authentication Logic Flaws

    Identifies flawed multi-step login flows, insecure password reset, and MFA bypass. Demonstrates that logic errors are as dangerous as missing input validation.

  • Lesson 4 • Cross-Site Request Forgery

    Crafts CSRF payloads that force authenticated users to perform unintended actions. Connects session management weaknesses to client-side attack vectors.

Chapter 6See details

Cross-Site Scripting and Client-Side Attacks

  • Lesson 1 • Clickjacking and UI Redressing

    Demonstrates iframe-based attacks that trick users into unintended clicks. Connects client-side attack knowledge to interface manipulation beyond script injection.

  • Lesson 2 • Content Security Policy and XSS Bypass

    Analyses CSP directives and demonstrates common misconfigurations that allow bypass. Prepares students to both evaluate defences and recommend correct CSP policies.

  • Lesson 3 • DOM-Based XSS

    Targets client-side JavaScript sinks that process attacker-controlled sources. Extends XSS skills to single-page applications and modern JavaScript frameworks.

  • Lesson 4 • Reflected and Stored XSS

    Distinguishes reflected from stored XSS and demonstrates payload delivery for each. Establishes XSS fundamentals before moving to DOM-based and advanced variants.

  • Lesson 5 • XSS Payload Weaponization

    Converts basic XSS into session theft, keylogging, and phishing overlays. Demonstrates real-world impact to justify remediation priority.

Chapter 7See details

Access Control and Business Logic Flaws

  • Lesson 1 • Broken Access Control Fundamentals

    Covers horizontal and vertical privilege escalation through parameter manipulation. Establishes the distinction between authentication and authorisation as attack targets.

  • Lesson 2 • Insecure Direct Object References

    Demonstrates IDOR in file downloads, API endpoints, and database record access. Builds systematic enumeration skills for finding exposed object references.

  • Lesson 3 • API Authorization Testing

    Tests REST and GraphQL APIs for missing authorisation checks and excessive data exposure. Extends access control skills to modern API-driven architectures.

  • Lesson 4 • Business Logic Vulnerability Testing

    Identifies flaws in purchase flows, discount logic, and multi-step workflows. Demonstrates that understanding application intent is essential for finding logic bugs.

Chapter 8See details

Advanced Exploitation and Post-Exploitation

  • Lesson 1 • Server-Side Request Forgery

    Forces the server to make internal requests, exposing cloud metadata and internal services. Demonstrates how SSRF bridges external access to internal network resources.

  • Lesson 2 • Professional Penetration Test Reporting

    Structures findings into a complete penetration test report with executive and technical sections. Translates technical exploitation results into actionable remediation guidance.

  • Lesson 3 • File Upload and Path Traversal Attacks

    Bypasses file upload restrictions to plant web shells and reads arbitrary server files. Combines injection and access control knowledge into server-level compromise.

  • Lesson 4 • Vulnerability Chaining and Pivoting

    Combines low-severity findings into high-impact exploit chains targeting critical assets. Develops strategic thinking required for advanced penetration testing engagements.

  • Lesson 5 • Deserialisation Vulnerabilities

    Exploits insecure deserialisation in Java, PHP, and Python applications for code execution. Extends injection concepts to object-level data manipulation.

Certification

Your valid completion certificate

This course is for you:

  • IT support professional: ready to pivot toward a security-focused technical career path.

  • Computer science student: wants practical offensive skills beyond what classrooms typically teach.

  • Network administrator: looking to understand threats from an attacker's point of view.

  • Career changer: drawn to cybersecurity and needs a structured, hands-on entry point.

  • Developer: wants to recognise and fix security flaws before attackers find them first.

  • Bug bounty beginner: has the curiosity but lacks a repeatable methodology to find vulnerabilities.

Related Courses

FAQ

Who is Dedika?

Is the certificate valid in Nigeria?

Are the courses free?

What is the course workload?

What are the courses like?

How do the courses work?

What is the duration of the courses?

What is the cost or price of the courses?

What is an EAD or online course and how does it work?

PDF Course