Skip to main content

Security Testing

OWASP Top 10, penetration testing basics, SQL injection, XSS, CSRF. Think like an attacker to defend like a pro.

advanced 3 courses 15 lessons

This path requires a Pro subscription

Subscribe to unlock all lessons, challenges, and bug hunts.

View pricing
1

Security Testing Fundamentals

The mindset, vocabulary, and landscape of security testing. Why every tester needs to think about security.

advanced ~3.0h
  • Requires subscription
    Why Security Testing Matters
    reading +10 XP
  • Requires subscription
    The OWASP Top 10 Overview
    reading +15 XP
  • Requires subscription
    Thinking Like an Attacker
    reading +15 XP
  • Requires subscription
    Security Testing vs Penetration Testing
    reading +15 XP
  • Requires subscription
    Setting Up a Safe Practice Environment
    reading +15 XP
2

Common Vulnerabilities

The vulnerabilities that cause the most damage. Understand how they work so you can find them before attackers do.

advanced ~5.0h
  • Requires subscription
    SQL Injection
    reading +20 XP
  • Requires subscription
    Cross-Site Scripting (XSS)
    reading +20 XP
  • Requires subscription
    Broken Authentication
    reading +15 XP
  • Requires subscription
    Broken Access Control
    reading +15 XP
  • Requires subscription
    Cross-Site Request Forgery (CSRF)
    reading +15 XP
3

Security Testing in Practice

Apply what you've learned. Tools, techniques, and workflows for integrating security testing into your daily work.

advanced ~4.0h
  • Requires subscription
    Security Headers and HTTPS
    reading +15 XP
  • Requires subscription
    API Security Testing
    reading +15 XP
  • Requires subscription
    Automated Security Scanning
    reading +15 XP
  • Requires subscription
    Writing Security Bug Reports
    reading +15 XP
  • Requires subscription
    Capstone: Security Assessment
    exercise +25 XP