Skip to contentExploitQuest
LearnWeb Application Security

Web Application Security

How web applications actually break, and how to stop yours breaking the same way. Every attack is paired with its defence, and every attack is run against something genuinely vulnerable rather than described.

Medium

Not yet reviewed

5 chapters18 lessons5 practice quizzes7 hands-on labs1 examabout 8hup to 880 XP

Before you start

This course expects those first. Nothing is locked — sign in and it will say where you stand.

Start the courseA Query Built From Pieces

The bug that comes from building a query out of string pieces. Where it comes from, what it lets somebody do, and the one-line habit that ends it.

Four-beat loop
  1. Attack
  2. Telemetry
  3. Fix
  4. Detection
6 lessons · 15 min
  1. A Query Built From Pieces1 min
  2. What Injection Is2 min
  3. Break It Yourself3 min
  4. The One-Line Fix3 min
  5. What The Database Saw3 min
  6. Catch It Next Time3 min
  7. Practice quiz26 questions

The application checks that you are logged in and forgets to check that the thing you asked for is yours. Where that gap comes from, what it hands over, and the check that has to happen on every object, every time.

Loop in progress
  1. Attack
  2. Telemetry
  3. Fix
  4. Detection
defensive beats coming
3 lessons · 8 min
  1. The Check That Never Ran2 min
  2. Walk To The Account3 min
  3. The Check On Every Object3 min
  4. Practice quiz8 questions

A filename is a path, and a path can climb. When an application builds a file path out of something you typed, `..` walks it out of the folder it was meant to stay in — and reads whatever the process can.

Loop in progress
  1. Attack
  2. Telemetry
  3. Fix
  4. Detection
defensive beats coming
3 lessons · 6 min
  1. A Name That Climbs2 min
  2. Read The Secrets Next Door2 min
  3. Keep It In The Folder2 min
  4. Practice quiz8 questions

A session token is only as strong as the check that verifies it. When the verifier accepts a token that declares its own signature unnecessary, anyone can write themselves a token that says whatever they like.

Loop in progress
  1. Attack
  2. Telemetry
  3. Fix
  4. Detection
defensive beats coming
3 lessons · 7 min
  1. What A Token Trusts2 min
  2. Forge The Token3 min
  3. Verify What You Issued2 min
  4. Practice quiz8 questions

The other four bugs let you break the server. This one lets you run code in somebody else's browser, with their session, from a value the page rendered without escaping it. A comment field becomes a way to become the moderator.

3 lessons · 9 min
  1. Whose Code Runs3 min
  2. Steal The Session3 min
  3. Escape On The Way Out3 min
  4. Practice quiz8 questions

Labs

Hands-on challenges for this course. Each one hides a flag you have to find.

  1. Climbing Out Of The Log Folderdifficulty 2
  2. Somebody Else's Statementdifficulty 2
  3. The Honest Mistakedifficulty 2
  4. The Moderator's Sessiondifficulty 2
  5. The Real Boarddifficulty 2
  6. The Profile Picturedifficulty 3
  7. The Token That Signs Itselfdifficulty 3

Exam

Timed, and it issues a credential anyone can verify. Practice quizzes are untimed; this one is not.

  1. Web Application Security Exam16 questions · pass at 70%