← All courses
66 lessons · 5.4 hoursCourse bundleLimited-time discount

Web Security Bundle

Get all web security courses from OpSecX at a discounted bundle price.

Offered by OpSecX

$104.96$79.99Log in to enroll

Course Overview

What this bundle covers

Web Security Bundle includes:

WebSecNinja: Lesser Known WebAttacks – WSN
Node.js Security: Pentesting and Exploitation – NJS
Cross Site Scripting (XSS) Attacks for Pentesters – XFP
XSSing JavaScript-MVC Applications -XJA

Syllabus

What you will learn

XSSing JS-MVC Applications - XJA

Introduction

  1. Introduction to the Course

    3 min

Javascript Refresher

  1. Basics of JavaScript

    10 min

  2. Object Proxying and Function Hooking

    10 min

Developer Tools

  1. Developer Tools & UserScripts

    7 min

MVC Frameworks

  1. Basic Architecture

    8 min

  2. Template Engines

    10 min

XSS Detection

  1. Ways of XSS Detection

    15 min

Case Studies

  1. HandlebarsJS

    16 min

  2. DustJS

    2 min

  3. AngularJS

    9 min

Conclusion

  1. Quick Recap & Conclusion

    3 min

  2. Course Slides

    Lesson

WebSecNinja: Lesser Known WebAttacks - WSN

Introduction to the Course

  1. Introduction

    2 min

  2. Source Code

    Lesson

RCE Attacks and Techniques

  1. Remote Command or OS Command Injection Basics

    7 min

  2. Blind RCE Injection

    6 min

  3. RCE Techniques and Cheat Sheet

    6 min

  4. Bypassing RCE Filter

    3 min

JSON Hijacking

  1. JSON Hijacking Basics

    3 min

  2. JSON Hijacking Demo

    5 min

Lesser Known XSS Variants

  1. mXSS or mutation XSS

    5 min

  2. rPO XSS or Relative Path Overwrite XSS

    5 min

Server Side Includes Injection (SSI Injection)

  1. Server Side Includes Injection Basics

    3 min

  2. Server Side Includes Injection Demo

    3 min

Server Side Request Forgery (SSRF)

  1. Server Side Request Forgery Basics

    3 min

  2. Exploiting an SSRF Vulnerability

    7 min

Reflected File Download (RFD)

  1. Reflected File Download (RFD) Theory

    8 min

  2. RFD Attack Explained

    12 min

Abusing Window.Opener Property

  1. Abusing JavaScript's window.opener property Theory

    4 min

  2. Phishing by abusing window.opener property

    1 min

Same Origin Method Execution (SOME)

  1. Same Origin Policy (SOP)

    4 min

  2. SOME Attack with Flash Callback explained

    5 min

  3. SOME Attack with Flash Callback Demo

    8 min

  4. Same Origin Method Execution Introduction

    7 min

Course Materials

  1. Course Slides

    Lesson

Node.js Security: Pentesting and Exploitation - NJS

Introduction

  1. Node.js Security: Pentesting and Exploitation - Overview

    1 min

  2. Introduction to Node.js

    2 min

Node.js Security Issues

  1. Global Namespace Pollution

    5 min

  2. HTTP Parameter Pollution (HPP)

    5 min

  3. Remote Code Execution with eval()

    6 min

  4. Remote OS Command Execution

    4 min

  5. Attacks due to Untrusted user input

    7 min

  6. Regex DoS

    4 min

Information Disclosure

  1. Information Disclosure in Node.js Web Applications

    3 min

Secure Coding

  1. Lack of Secure Code in Node.js

    2 min

Code Review

  1. How to do Code Review of a Node.js Application

    3 min

Automated Code Review

  1. Automated Code Review of Node.js Application with NodeJsScan

    26 min

Conclusion

  1. Conclusion

    1 min

  2. Course Slides

    Lesson

Cross Site Scripting (XSS) Attacks for Pentesters - XFP

Introduction

  1. Introduction to Cross Site Scripting (XSS) Attacks for Pentesters

    2 min

  2. What, Why and Types of XSS

    2 min

Types of XSS

  1. Reflected XSS or Non-Persistent XSS

    3 min

  2. Stored XSS or Persistent XSS

    3 min

  3. DOM XSS

    4 min

  4. mXSS or Mutation XSS

    5 min

  5. RPO or Relative Path Overwrite XSS

    5 min

Source of XSS

  1. What are the different Sources of XSS?

    3 min

Different Contexts in XSS

  1. HTML Context

    2 min

  2. Attribute Context

    5 min

  3. URL Context

    3 min

  4. Style Context

    3 min

  5. Script Context

    3 min

XSS Attacks in Realworld

  1. Exploiting XSS with OWASP Xenotix XSS Exploit Framework

    8 min

XSS Protection

  1. XSS Protection

    5 min

  2. XSS Protection Cheatsheet

    Lesson

Course PDF

  1. Course Slides

    Lesson

Frequently asked questions

What is Web Security Bundle?

Get all web security courses from OpSecX at a discounted bundle price. Offered by OpSecX as self-paced training.

Who is this training for?

This bundle is for pentesters, developers, and security practitioners who want hands-on application security skills they can use on real systems.

How long is the training?

The bundle includes 66 lessons · 5.4 hours. You work through it at your own pace.

Which courses are included?

Web Security Bundle includes: XSSing JS-MVC Applications - XJA; WebSecNinja: Lesser Known WebAttacks - WSN; Node.js Security: Pentesting and Exploitation - NJS; Cross Site Scripting (XSS) Attacks for Pentesters - XFP.

Do I get a certificate?

Yes. Completing a course issues a verifiable OpSecX certificate with a public verification link. You control whether your name is shown on that page.

How do I access the lessons?

After purchase, lessons are available self-paced in your OpSecX dashboard. Preview lessons on this page do not require enrollment.