Choose your language
Advanced Network Attacks, Web Hacking, and Cryptography Course
More than 2 million students worldwide

Advanced Network Attacks, Web Hacking, and Cryptography Course

Master the full offensive security stack — from packet-level network attacks and OWASP Top 10 web exploitation to real-world cryptographic vulnerabilities. This advanced course delivers hands-on skills across network hacking, web application penetration testing, and applied cryptography. Built for security professionals ready to operate at a higher level and prove it.

Dedika for businesses

What you will learn:

  • Execute ARP poisoning, DNS cache poisoning, and man-in-the-middle attacks on live network environments.

  • Exploit SQL injection, XSS, IDOR, SSRF, and command injection vulnerabilities in web applications.

  • Analyze TLS handshakes and attack weak cipher suites using POODLE, BEAST, and downgrade techniques.

  • Perform advanced web attacks including JWT manipulation, OAuth flow hijacking, and SSTI exploitation.

  • Conduct full reconnaissance using Nmap, Amass, Shodan, and passive OSINT techniques against real targets.

  • Build professional penetration test reports with risk-rated findings and actionable remediation guidance.

How you study in practice Advanced Network Attacks, Web Hacking, and Cryptography Course

How you practice Advanced Network Attacks, Web Hacking, and Cryptography Course

For companies that want to train their team

With Dedika for Business, the course includes exercises and examples tailored to your own business and the way your company needs.

Click here

Course content

8 Chapters • 38 LessonsDuration between 4 and 360 hours (you decide)

Chapter 1See details

Networking Fundamentals for Security Professionals

  • Lesson 1 • TCP/IP Stack and Protocol Internals

    Covers the layered protocol model, IP addressing, and TCP handshake mechanics. Establishes the mental model needed to understand how attacks exploit protocol behavior.

  • Lesson 2 • Firewalls, NAT, and Network Segmentation

    Examines stateful inspection, NAT traversal, and VLAN-based segmentation. Students learn to identify filtering rules that must be bypassed during penetration engagements.

  • Lesson 3 • Network Traffic Analysis with Wireshark

    Teaches live and offline packet capture, filtering, and protocol dissection. Connects directly to later attack chapters by training students to observe malicious traffic patterns.

  • Lesson 4 • DNS, DHCP, and ARP Operations

    Explains how name resolution, address assignment, and layer-2 mapping work. Understanding these protocols is prerequisite to spoofing and poisoning attacks covered later.

Chapter 2See details

Reconnaissance and Target Enumeration

  • Lesson 1 • Vulnerability Scanning and Risk Prioritization

    Uses automated scanners to identify known weaknesses and maps findings to severity scores. Students learn to filter false positives and prioritize targets for manual exploitation.

  • Lesson 2 • Passive Open-Source Intelligence Gathering

    Covers WHOIS, certificate transparency logs, search engine dorking, and social media mining. Passive OSINT leaves no footprint on the target and is always the first recon phase.

  • Lesson 3 • Active Network Scanning with Nmap

    Teaches host discovery, port scanning, service versioning, and OS fingerprinting using Nmap. Active scanning generates detectable traffic, so students learn timing and evasion options.

  • Lesson 4 • Service Enumeration and Banner Grabbing

    Extracts version strings, configuration details, and user lists from exposed services. This data feeds directly into vulnerability identification and exploit selection.

  • Lesson 5 • DNS Enumeration and Subdomain Discovery

    Applies zone transfers, brute-force wordlists, and certificate data to map all DNS records. Comprehensive DNS mapping expands the attack surface before exploitation begins.

Chapter 3See details

Network Attack Techniques and Exploitation

  • Lesson 1 • DNS Spoofing and Cache Poisoning

    Manipulates DNS responses to redirect victims to attacker-controlled servers. Covers both local network spoofing and remote cache poisoning against resolvers.

  • Lesson 2 • Password Attacks and Credential Exploitation

    Covers online brute-forcing, credential stuffing, and offline hash cracking against network services. Students apply captured hashes and credentials to gain authenticated access.

  • Lesson 3 • Man-in-the-Middle Interception and SSL Stripping

    Chains ARP poisoning with traffic interception to capture credentials and session tokens. SSL stripping downgrades HTTPS connections to expose plaintext data.

  • Lesson 4 • Exploitation Frameworks and Payload Delivery

    Introduces Metasploit for selecting, configuring, and launching exploits against enumerated services. Students learn payload staging, handler setup, and session management.

  • Lesson 5 • ARP Poisoning and Layer-2 Attacks

    Demonstrates ARP cache poisoning to redirect traffic through an attacker-controlled host. Builds directly on ARP mechanics from Chapter 1 and recon data from Chapter 2.

Chapter 4See details

Web Application Security Fundamentals

  • Lesson 1 • Web Application Enumeration and Mapping

    Discovers hidden directories, parameters, and endpoints using automated tools and manual browsing. Complete application mapping ensures no attack surface is overlooked.

  • Lesson 2 • Web Proxy Setup and Traffic Manipulation

    Configures Burp Suite as an intercepting proxy to inspect, modify, and replay web requests. Proxy mastery is the core skill enabling all manual web vulnerability testing.

  • Lesson 3 • Authentication and Session Management Analysis

    Analyzes login mechanisms, session token entropy, and cookie security attributes. Weaknesses found here are exploited in later chapters on authentication bypass.

  • Lesson 4 • HTTP Protocol and Web Architecture

    Examines HTTP/1.1 and HTTP/2 request-response cycles, headers, cookies, and status codes. This protocol fluency is the prerequisite for every web attack technique that follows.

Chapter 5See details

OWASP Top 10 and Injection Attacks

  • Lesson 1 • CSRF, SSRF, and Security Misconfigurations

    Exploits cross-site request forgery, server-side request forgery, and common server misconfigurations. SSRF is particularly critical for cloud-hosted applications.

  • Lesson 2 • Cross-Site Scripting: Reflected, Stored, and DOM

    Demonstrates all three XSS variants, from payload crafting to session hijacking and phishing. Students learn context-aware encoding bypass to defeat common filters.

  • Lesson 3 • SQL Injection: Detection and Exploitation

    Teaches manual and automated SQL injection across error-based, blind, and out-of-band channels. Students extract databases, bypass authentication, and escalate to OS command execution.

  • Lesson 4 • Command Injection and File Inclusion Attacks

    Exploits server-side command execution and file inclusion to achieve remote code execution. These attacks leverage insufficient input validation on the server.

  • Lesson 5 • Broken Access Control and IDOR

    Identifies and exploits insecure direct object references, privilege escalation, and missing function-level access controls. Access control flaws are the most prevalent web vulnerability class.

Chapter 6See details

Cryptography Principles and Applied Attacks

  • Lesson 1 • Hashing, MACs, and Integrity Attacks

    Covers cryptographic hash functions, HMAC construction, and attacks including length extension and collision. Integrity failures enable forgery of tokens, signatures, and file checksums.

  • Lesson 2 • TLS Protocol Analysis and Downgrade Attacks

    Analyzes TLS 1.2 and 1.3 handshakes and exploits legacy cipher suites and downgrade vulnerabilities. TLS weaknesses directly enable network interception attacks.

  • Lesson 3 • Padding Oracle and Cryptographic Side-Channel Attacks

    Exploits padding validation errors and timing differences to decrypt ciphertext without the key. These attacks demonstrate that implementation flaws can break mathematically sound algorithms.

  • Lesson 4 • Symmetric Encryption and Block Cipher Modes

    Covers AES internals, block cipher modes, and the security implications of each mode. Understanding cipher modes is essential for attacking padding oracles and ECB weaknesses.

  • Lesson 5 • Asymmetric Cryptography and PKI

    Explains RSA, elliptic curve cryptography, and the public key infrastructure that underpins TLS. Students learn how weak key generation and certificate mismanagement create exploitable flaws.

Chapter 7See details

Advanced Web Exploitation Techniques

  • Lesson 1 • Server-Side Template Injection

    Identifies and exploits template injection in popular engines to achieve remote code execution. SSTI requires recognizing template syntax and engine-specific payload construction.

  • Lesson 2 • XML and Deserialization Vulnerabilities

    Exploits XXE injection and insecure deserialization to read files, perform SSRF, and achieve RCE. These vulnerabilities require understanding of data serialization formats.

  • Lesson 3 • Web Cache Poisoning and HTTP Request Smuggling

    Exploits caching infrastructure and HTTP parsing discrepancies to poison responses and smuggle requests. These advanced techniques affect large-scale web infrastructure.

  • Lesson 4 • API Security Testing and GraphQL Attacks

    Tests REST and GraphQL APIs for authentication flaws, injection, and excessive data exposure. API attack surface differs significantly from traditional web applications.

  • Lesson 5 • OAuth 2.0 and JWT Attack Techniques

    Targets flaws in OAuth flows and JSON Web Token implementations to hijack accounts and escalate privileges. Modern applications rely heavily on these authentication standards.

Chapter 8See details

Post-Exploitation, Pivoting, and Reporting

  • Lesson 1 • Privilege Escalation on Linux and Windows

    Identifies and exploits misconfigurations, weak permissions, and kernel vulnerabilities to gain root or SYSTEM access. Privilege escalation is the critical step between foothold and full compromise.

  • Lesson 2 • Persistence and Defense Evasion

    Establishes persistent access through scheduled tasks, registry keys, and web shells while evading detection. Students understand attacker persistence to better design defensive controls.

  • Lesson 3 • Penetration Test Reporting and Communication

    Structures findings into executive summaries and technical reports with reproducible proof-of-concept steps. Clear reporting translates technical findings into actionable remediation guidance.

  • Lesson 4 • Lateral Movement and Pivoting Techniques

    Uses compromised hosts as pivot points to reach otherwise inaccessible network segments. Pivoting extends the attack into internal networks discovered during reconnaissance.

  • Lesson 5 • Data Exfiltration Methods

    Demonstrates techniques for extracting sensitive data over covert channels while avoiding detection. Understanding exfiltration paths informs data loss prevention control design.

Certification

Your valid completion certificate

This course is for you:

  • Junior penetration testers: ready to move beyond basic scanning into real exploitation.

  • IT network administrators: wanting to understand how attackers target their infrastructure.

  • Computer science graduates: transitioning into offensive security as a first career move.

  • Bug bounty hunters: seeking structured depth behind the vulnerabilities they already chase.

  • SOC analysts: building attacker empathy to sharpen their detection and response skills.

  • Self-taught hobbyists: who have outgrown beginner CTFs and need professional-grade technique.

What our students say

Your classes are perfect. I purchased the one-year package and finally have the opportunity to follow various topics of my interest without needing to switch platforms... I thank you for everything you do, I've already recommended you to other people...
Giulio Carlo
Giulio CarloDigital Marketing Student
I like how the lessons are straight to the point and how I can switch chapters and skip content I don't need.
Mariana Ferres
Mariana FerresPhotography Student
I like the content and the presentation style and video transcription, which speeds up the process!
Luciana Alvarenga
Luciana AlvarengaNail Design Student
The platform is fast, simple to use. The diversity of content and complementary videos really help with learning.
André Felipe
André FelipePrompt Engineering Student

Top trainings

FAQ

Who is Dedika?

Is the certificate valid in the United States?

Are the courses free?

What is the course workload?

What are the courses like?

How do the courses work?

What is the duration of the courses?

What is the cost or price of the courses?

What is an EAD or online course and how does it work?

PDF Course