
Advanced Network Attacks, Web Hacking, and Cryptography Course
Master the full offensive security stack — from packet-level network attacks and OWASP Top 10 web exploitation to real-world cryptographic vulnerabilities. This advanced course delivers hands-on skills across network hacking, web application penetration testing, and applied cryptography. Built for security professionals ready to operate at a higher level and prove it.
What you will learn:
Execute ARP poisoning, DNS cache poisoning, and man-in-the-middle attacks on live network environments.
Exploit SQL injection, XSS, IDOR, SSRF, and command injection vulnerabilities in web applications.
Analyse TLS handshakes and attack weak cipher suites using POODLE, BEAST, and downgrade techniques.
Perform advanced web attacks including JWT manipulation, OAuth flow hijacking, and SSTI exploitation.
Conduct full reconnaissance using Nmap, Amass, Shodan, and passive OSINT techniques against real targets.
Build professional penetration test reports with risk-rated findings and actionable remediation guidance.
How you study in practice Advanced Network Attacks, Web Hacking, and Cryptography Course
How you practise Advanced Network Attacks, Web Hacking, and Cryptography Course
For companies looking to train their teams
With Dedika for Businesses, the course includes exercises and examples tailored to your own business and the specific needs of your company.
Course content
8 Chapters • 38 LessonsDuration between 4 and 360 hours (you decide)
Chapter 1HideHide detailsSee detailsNetworking Fundamentals for Security Professionals
Networking Fundamentals for Security Professionals
Lesson 1 • TCP/IP Stack and Protocol Internals
Covers the layered protocol model, IP addressing, and TCP handshake mechanics. Establishes the mental model needed to understand how attacks exploit protocol behaviour.
Lesson 2 • Firewalls, NAT, and Network Segmentation
Examines stateful inspection, NAT traversal, and VLAN-based segmentation. Students learn to identify filtering rules that must be bypassed during penetration engagements.
Lesson 3 • Network Traffic Analysis with Wireshark
Teaches live and offline packet capture, filtering, and protocol dissection. Connects directly to later attack chapters by training students to observe malicious traffic patterns.
Lesson 4 • DNS, DHCP, and ARP Operations
Explains how name resolution, address assignment, and layer-2 mapping work. Understanding these protocols is prerequisite to spoofing and poisoning attacks covered later.
Chapter 2HideHide detailsSee detailsReconnaissance and Target Enumeration
Reconnaissance and Target Enumeration
Lesson 1 • Vulnerability Scanning and Risk Prioritization
Uses automated scanners to identify known weaknesses and maps findings to severity scores. Students learn to filter false positives and prioritise targets for manual exploitation.
Lesson 2 • Passive Open-Source Intelligence Gathering
Covers WHOIS, certificate transparency logs, search engine dorking, and social media mining. Passive OSINT leaves no footprint on the target and is always the first recon phase.
Lesson 3 • Active Network Scanning with Nmap
Teaches host discovery, port scanning, service versioning, and OS fingerprinting using Nmap. Active scanning generates detectable traffic, so students learn timing and evasion options.
Lesson 4 • Service Enumeration and Banner Grabbing
Extracts version strings, configuration details, and user lists from exposed services. This data feeds directly into vulnerability identification and exploit selection.
Lesson 5 • DNS Enumeration and Subdomain Discovery
Applies zone transfers, brute-force wordlists, and certificate data to map all DNS records. Comprehensive DNS mapping expands the attack surface before exploitation begins.
Chapter 3HideHide detailsSee detailsNetwork Attack Techniques and Exploitation
Network Attack Techniques and Exploitation
Lesson 1 • DNS Spoofing and Cache Poisoning
Manipulates DNS responses to redirect victims to attacker-controlled servers. Covers both local network spoofing and remote cache poisoning against resolvers.
Lesson 2 • Password Attacks and Credential Exploitation
Covers online brute-forcing, credential stuffing, and offline hash cracking against network services. Students apply captured hashes and credentials to gain authenticated access.
Lesson 3 • Man-in-the-Middle Interception and SSL Stripping
Chains ARP poisoning with traffic interception to capture credentials and session tokens. SSL stripping downgrades HTTPS connections to expose plaintext data.
Lesson 4 • Exploitation Frameworks and Payload Delivery
Introduces Metasploit for selecting, configuring, and launching exploits against enumerated services. Students learn payload staging, handler setup, and session management.
Lesson 5 • ARP Poisoning and Layer-2 Attacks
Demonstrates ARP cache poisoning to redirect traffic through an attacker-controlled host. Builds directly on ARP mechanics from Chapter 1 and recon data from Chapter 2.
Chapter 4HideHide detailsSee detailsWeb Application Security Fundamentals
Web Application Security Fundamentals
Lesson 1 • Web Application Enumeration and Mapping
Discovers hidden directories, parameters, and endpoints using automated tools and manual browsing. Complete application mapping ensures no attack surface is overlooked.
Lesson 2 • Web Proxy Setup and Traffic Manipulation
Configures Burp Suite as an intercepting proxy to inspect, modify, and replay web requests. Proxy mastery is the core skill enabling all manual web vulnerability testing.
Lesson 3 • Authentication and Session Management Analysis
Analyses login mechanisms, session token entropy, and cookie security attributes. Weaknesses found here are exploited in later chapters on authentication bypass.
Lesson 4 • HTTP Protocol and Web Architecture
Examines HTTP/1.1 and HTTP/2 request-response cycles, headers, cookies, and status codes. This protocol fluency is the prerequisite for every web attack technique that follows.
Chapter 5HideHide detailsSee detailsOWASP Top 10 and Injection Attacks
OWASP Top 10 and Injection Attacks
Lesson 1 • CSRF, SSRF, and Security Misconfigurations
Exploits cross-site request forgery, server-side request forgery, and common server misconfigurations. SSRF is particularly critical for cloud-hosted applications.
Lesson 2 • Cross-Site Scripting: Reflected, Stored, and DOM
Demonstrates all three XSS variants, from payload crafting to session hijacking and phishing. Students learn context-aware encoding bypass to defeat common filters.
Lesson 3 • SQL Injection: Detection and Exploitation
Teaches manual and automated SQL injection across error-based, blind, and out-of-band channels. Students extract databases, bypass authentication, and escalate to OS command execution.
Lesson 4 • Command Injection and File Inclusion Attacks
Exploits server-side command execution and file inclusion to achieve remote code execution. These attacks leverage insufficient input validation on the server.
Lesson 5 • Broken Access Control and IDOR
Identifies and exploits insecure direct object references, privilege escalation, and missing function-level access controls. Access control flaws are the most prevalent web vulnerability class.
Chapter 6HideHide detailsSee detailsCryptography Principles and Applied Attacks
Cryptography Principles and Applied Attacks
Lesson 1 • Hashing, MACs, and Integrity Attacks
Covers cryptographic hash functions, HMAC construction, and attacks including length extension and collision. Integrity failures enable forgery of tokens, signatures, and file checksums.
Lesson 2 • TLS Protocol Analysis and Downgrade Attacks
Analyzes TLS 1.2 and 1.3 handshakes and exploits legacy cipher suites and downgrade vulnerabilities. TLS weaknesses directly enable network interception attacks.
Lesson 3 • Padding Oracle and Cryptographic Side-Channel Attacks
Exploits padding validation errors and timing differences to decrypt ciphertext without the key. These attacks demonstrate that implementation flaws can break mathematically sound algorithms.
Lesson 4 • Symmetric Encryption and Block Cipher Modes
Covers AES internals, block cipher modes, and the security implications of each mode. Understanding cipher modes is essential for attacking padding oracles and ECB weaknesses.
Lesson 5 • Asymmetric Cryptography and PKI
Explains RSA, elliptic curve cryptography, and the public key infrastructure that underpins TLS. Students learn how weak key generation and certificate mismanagement create exploitable flaws.
Chapter 7HideHide detailsSee detailsAdvanced Web Exploitation Techniques
Advanced Web Exploitation Techniques
Lesson 1 • Server-Side Template Injection
Identifies and exploits template injection in popular engines to achieve remote code execution. SSTI requires recognizing template syntax and engine-specific payload construction.
Lesson 2 • XML and Deserialization Vulnerabilities
Exploits XXE injection and insecure deserialization to read files, perform SSRF, and achieve RCE. These vulnerabilities require understanding of data serialization formats.
Lesson 3 • Web Cache Poisoning and HTTP Request Smuggling
Exploits caching infrastructure and HTTP parsing discrepancies to poison responses and smuggle requests. These advanced techniques affect large-scale web infrastructure.
Lesson 4 • API Security Testing and GraphQL Attacks
Tests REST and GraphQL APIs for authentication flaws, injection, and excessive data exposure. API attack surface differs significantly from traditional web applications.
Lesson 5 • OAuth 2.0 and JWT Attack Techniques
Targets flaws in OAuth flows and JSON Web Token implementations to hijack accounts and escalate privileges. Modern applications rely heavily on these authentication standards.
Chapter 8HideHide detailsSee detailsPost-Exploitation, Pivoting, and Reporting
Post-Exploitation, Pivoting, and Reporting
Lesson 1 • Privilege Escalation on Linux and Windows
Identifies and exploits misconfigurations, weak permissions, and kernel vulnerabilities to gain root or SYSTEM access. Privilege escalation is the critical step between foothold and full compromise.
Lesson 2 • Persistence and Defense Evasion
Establishes persistent access through scheduled tasks, registry keys, and web shells while evading detection. Students understand attacker persistence to better design defensive controls.
Lesson 3 • Penetration Test Reporting and Communication
Structures findings into executive summaries and technical reports with reproducible proof-of-concept steps. Clear reporting translates technical findings into actionable remediation guidance.
Lesson 4 • Lateral Movement and Pivoting Techniques
Uses compromised hosts as pivot points to reach otherwise inaccessible network segments. Pivoting extends the attack into internal networks discovered during reconnaissance.
Lesson 5 • Data Exfiltration Methods
Demonstrates techniques for extracting sensitive data over covert channels while avoiding detection. Understanding exfiltration paths informs data loss prevention control design.
Your valid completion certificate
This course is for you:
Junior penetration testers: ready to move beyond basic scanning into real exploitation.
IT network administrators: wanting to understand how attackers target their infrastructure.
Computer science graduates: transitioning into offensive security as a first career move.
Bug bounty hunters: seeking structured depth behind the vulnerabilities they already chase.
SOC analysts: building attacker empathy to sharpen their detection and response skills.
Self-taught hobbyists: who have outgrown beginner CTFs and need professional-grade technique.
What our students say
Your lessons are perfect. I purchased the one-year package and finally have the opportunity to follow various topics of my interest without needing to change platforms... I'm grateful for everything you do, I've already recommended you to other people...

I like how the lessons are straight to the point and how I can change chapters and skip content I don't need.

I like the content and the way videos are presented and transcribed, which speeds up the process!

The platform is fast, simple to use. The diversity of content and complementary videos help a lot with learning.

Top trainings
FAQs
Who is Dedika?
Is the certificate valid in Pakistan?
Are the courses free?
What is the course workload?
What are the courses like?
How do the courses work?
What is the duration of the courses?
What is the cost or price of the courses?
What is an EAD or online course and how does it work?
PDF Course




















