Web Application Security
How web applications actually break, and how to stop yours breaking the same way. Every attack is paired with its defence, and every attack is run against something genuinely vulnerable rather than described.
Not yet reviewed
Before you start
- Introduction to ExploitQuestabout 1h
This course expects those first. Nothing is locked — sign in and it will say where you stand.
The bug that comes from building a query out of string pieces. Where it comes from, what it lets somebody do, and the one-line habit that ends it.
- Attack
- Telemetry
- Fix
- Detection
The application checks that you are logged in and forgets to check that the thing you asked for is yours. Where that gap comes from, what it hands over, and the check that has to happen on every object, every time.
- Attack
- Telemetry
- Fix
- Detection
A filename is a path, and a path can climb. When an application builds a file path out of something you typed, `..` walks it out of the folder it was meant to stay in — and reads whatever the process can.
- Attack
- Telemetry
- Fix
- Detection
A session token is only as strong as the check that verifies it. When the verifier accepts a token that declares its own signature unnecessary, anyone can write themselves a token that says whatever they like.
- Attack
- Telemetry
- Fix
- Detection
The other four bugs let you break the server. This one lets you run code in somebody else's browser, with their session, from a value the page rendered without escaping it. A comment field becomes a way to become the moderator.
Labs
Hands-on challenges for this course. Each one hides a flag you have to find.
Exam
Timed, and it issues a credential anyone can verify. Practice quizzes are untimed; this one is not.