Modern Web Application & API Penetration Testing
A rigorous 5-day hands-on programme designed for security professionals who need to test modern web applications and APIs effectively. You will master the full attack surface of SPA and API-driven applications, advanced Burp Suite workflows, authentication & authorization flaws, server-side …
Overview
A rigorous 5-day hands-on programme designed for security professionals who need to test modern web applications and APIs effectively.
You will master the full attack surface of SPA and API-driven applications, advanced Burp Suite workflows, authentication & authorization flaws, server-side vulnerabilities, GraphQL and modern API testing, multi-step attack chaining, and professional reporting — all performed inside a private, instructor-provisioned lab environment.
By the end of the course you will be able to independently map, exploit, chain, and professionally report high-impact findings on real-world modern web and API targets.
What You’ll Build / Achieve in 5 Days
- Day 1: Full attack-surface map of a modern SPA + discovery of hidden endpoints and client-side secrets through JavaScript analysis.
- Day 2: Forged JWT privilege escalation + IDOR/BOLA exploitation chained into stored XSS session takeover.
- Day 3: Confirmed injection + data extraction, plus SSRF into an internal-only service.
- Day 4: Complete OWASP API Security Top 10 sweep on a REST API + GraphQL schema recovery leading to cross-tenant data access.
- Day 5 (Capstone): Full assessment of a fresh multi-service target, multi-finding attack chain into one critical impact, and a short professional report presentation.
Tools & Techniques You’ll Master
- Advanced Burp Suite (workflow, extensions, BApps)
- JavaScript & SPA analysis (source maps, client-side secrets)
- JWT / OAuth 2.0 / OpenID Connect testing
- OWASP API Security Top 10 methodology
- GraphQL introspection & authorization testing
- Injection families (SQL, NoSQL, SSTI, command, XXE)
- SSRF, file upload, path traversal, request smuggling
- Automation tools: ffuf, nuclei, sqlmap
- Multi-step attack chaining & business-logic abuse
- Professional reporting, CVSS & remediation guidance
Day-by-Day Curriculum
DAY 1 | Modern Web & API Attack Surface / Advanced Burp Workflow
- Modern web architecture: SPA, JavaScript, JSON and API-driven applications
- Web and API reconnaissance, fingerprinting and attack-surface mapping
- Advanced Burp Suite workflow and project configuration
- Endpoint, parameter, content and hidden-function discovery
- JavaScript analysis, source maps, exposed endpoints and client-side secrets
- Manual request manipulation, replay, fuzzing and response analysis
- Testing methodology, scoping and evidence collection
Demo: Instructor mines a lab SPA’s JavaScript bundle live to uncover a hidden API endpoint and a leaked key.
Task: Participants map the lab target’s full attack surface and locate a hidden admin function through discovery and JS analysis.
DAY 2 | Authentication, Session, Authorization & Client-Side Security
- Authentication and session-management security testing
- JWT, OAuth 2.0, OpenID Connect and token security
- MFA, OTP, password reset, device trust and account-recovery testing
- Broken access control, IDOR/BOLA, privilege escalation and role bypass
- CSRF, CORS, clickjacking and cross-origin security controls
- Reflected, stored and DOM-based XSS testing
- DOM security, prototype pollution and modern client-side attack surfaces
Demo: Instructor forges a lab JWT to escalate from standard user to admin.
Task: Participants find and exploit an IDOR/BOLA on the lab API, then chain a stored XSS into session takeover.
DAY 3 | Advanced Server-Side Vulnerabilities & Exploitation
- SQL, NoSQL, command and server-side template injection
- SSRF and server-side request manipulation
- XXE, insecure deserialization and parser-related attacks
- File upload, path traversal and local file exposure
- HTTP request smuggling/desynchronization and cache-based attacks
- Race conditions, concurrency flaws and state-manipulation testing
- Advanced input-validation bypass and vulnerability chaining
Demo: Instructor bypasses a lab upload filter to plant a web shell, then chains a path-traversal read.
Task: Participants find a confirmed injection point on the lab target and extract data, then attempt an SSRF into an internal-only lab service.
DAY 4 | Advanced API Penetration Testing
- REST API security testing and OWASP API Security Top 10 coverage
- GraphQL security testing, introspection and authorization review
- WebSocket, gRPC and modern service-interface security testing
- API authentication, object/function-level authorization and tenant isolation
- Mass assignment, parameter pollution and excessive data exposure
- Rate limiting, resource consumption, automation and bot-abuse testing
- Swagger/OpenAPI/Postman-assisted testing, fuzzing and API discovery
- Financial and transaction API business-logic security use cases
Demo: Instructor uses GraphQL introspection on the lab API to recover the schema and reach another tenant’s data.
Task: Participants run the lab REST API through an OWASP API Top 10 sweep and confirm a mass-assignment or BOLA finding.
DAY 5 | Advanced Attack Chaining, Automation & Professional Delivery
- Complex business-logic and workflow manipulation
- Multi-step attack chaining and impact validation
- WAF/filter bypass concepts and resilient manual testing techniques
- Automated reconnaissance and validation with Burp, ffuf, nuclei and sqlmap
- Burp extensions, BApps and introduction to custom extension development
- Vulnerability prioritization, CVSS and business-impact assessment
- Professional evidence, reporting, remediation guidance and retesting
- Capstone web/API penetration test and findings presentation
Demo: Instructor chains three lower-severity lab findings into one critical account-takeover exploit.
Task (Capstone): Participants run a full assessment on a fresh multi-service lab target, chain findings into one high-impact exploit, and present a short professional report.
Note: All demos and tasks are performed on a private lab environment provisioned by the instructor.
Capstone Project
On Day 5 you will perform a full, independent penetration test against a fresh multi-service lab target.
You must:
- Discover and exploit multiple vulnerabilities
- Chain findings into one high-impact exploit
- Produce and present a short professional report with evidence, impact assessment, and remediation guidance
This mirrors real-world consulting engagements.
Requirements
- Solid understanding of HTTP, web application fundamentals, and basic web vulnerabilities (XSS, SQLi, etc.)
- Familiarity with Burp Suite (or equivalent intercepting proxy)
- Comfortable working in a Linux environment and using the command line
- Laptop capable of running virtual machines / Docker (private lab access will be provided)
- No prior GraphQL or advanced API testing experience is required — these topics are covered thoroughly during the course.
Features
- Fully Hands-On – Every day includes live instructor demos + individual participant tasks inside a private lab
- Private Lab Environment – Dedicated, instructor-provisioned lab targets (SPA + multi-service APIs) – no shared or public labs
- Modern Attack Surface Focus – Deep coverage of SPAs, JavaScript analysis, REST, GraphQL, WebSocket & gRPC
- Advanced Burp Suite Mastery – Project configuration, advanced workflows, extensions, and introduction to custom BApp development
- Real Attack Chaining – Learn to combine lower-severity findings into high-impact exploits (account takeover, data breach, etc.)
- Complete API Coverage – Full OWASP API Security Top 10 + GraphQL introspection, mass assignment, tenant isolation & business-logic flaws
Target audiences
- Penetration testers and red teamers who need to level up on modern SPAs and APIs
- Application security engineers and DevSecOps practitioners
- Bug bounty hunters targeting complex web and API applications
- Security consultants preparing for advanced web/API engagements
- Developers and architects who want deep offensive insight into modern application security






