Week 4

Web exploitation and the pentesting toolchain

Apply web attacks in challenge rooms, research vulnerabilities, test passwords responsibly, and begin exploitation with Metasploit.

Day 22 planned

Session management and broken authentication

Complete Session Management and Broken Authentication, then compare how the application handles identity across requests.

Open daily log
Day 23 planned

File inclusion and command injection

Complete File Inclusion and Command Injection, then practise distinguishing file-path handling from shell execution.

Open daily log
Day 24 planned

API pentesting and Support

Complete API Pentesting, then attempt Support with an endpoint inventory and evidence-led testing process.

Open daily log
Day 25 planned

Vulnerability research and validation

Learn to move from version evidence to a defensible vulnerability hypothesis without treating scanner output as proof.

Open daily log
Day 26 planned

Hydra and targeted wordlists

Complete Hydra and Introduction to Wordlists, then compare a small targeted list with a generic list on the authorised lab.

Open daily log
Day 27 planned

Password cracking and Checkmate

Complete Password Cracking, then apply hash identification and cracking decisions independently in Checkmate.

Open daily log
Day 28 planned

Metasploit basics and exploitation

Complete Metasploit: The Basics and Scanning and Exploitation, then document the path from evidence to a selected module.

Open daily log