Week 4
Web exploitation and the pentesting toolchain
Apply web attacks in challenge rooms, research vulnerabilities, test passwords responsibly, and begin exploitation with Metasploit.
Session management and broken authentication
Complete Session Management and Broken Authentication, then compare how the application handles identity across requests.
Open daily logFile inclusion and command injection
Complete File Inclusion and Command Injection, then practise distinguishing file-path handling from shell execution.
Open daily logAPI pentesting and Support
Complete API Pentesting, then attempt Support with an endpoint inventory and evidence-led testing process.
Open daily logVulnerability research and validation
Learn to move from version evidence to a defensible vulnerability hypothesis without treating scanner output as proof.
Open daily logHydra and targeted wordlists
Complete Hydra and Introduction to Wordlists, then compare a small targeted list with a generic list on the authorised lab.
Open daily logPassword cracking and Checkmate
Complete Password Cracking, then apply hash identification and cracking decisions independently in Checkmate.
Open daily logMetasploit basics and exploitation
Complete Metasploit: The Basics and Scanning and Exploitation, then document the path from evidence to a selected module.
Open daily log