The route
06
Offensive · stage 6 of 10
Advanced Web Exploitation
The eleven sessions that separate a scanner operator from a tester: authentication bypass and 2FA defeat, information disclosure, both HTTP request smuggling desyncs, business logic flaws, host header attacks and directory traversal.
Advanced11 sessions15 h 40 mSessions 49–52, 55–58, 61–63
Get full access · ₹699
This module is included — it is not sold on its own.

// Sessions in this module
4 sections · 11 sessions · 15 h 40 m
Authentication and information disclosure6 h 33 m
- 01Authentication vulnerabilities · PortSwigger labs1:44:12
- 02Authentication bypass · 2FA and 2FA bypass · Brute-forcing credentials1:36:04
- 03Information disclosure vulnerabilities1:46:20
- 04Information disclosure labs1:26:01
HTTP request smuggling3 h 7 m
Both desync variants, with the smuggler tool driven on screen.
- 01HTTP request smuggling · CL.TE · The smuggler tool1:32:46
- 02HTTP request smuggling · TE.CL · PortSwigger labs1:34:29
Business logic and host header attacks3 h 29 m
- 01Business logic flaws · Password reset vulnerabilities · PortSwigger labs1:29:53
- 02PortSwigger labs · Logical vulnerabilities39:18
- 03Host header attacks · PortSwigger labs1:19:55
Traversal, DoS and Hacker101 CTFs2 h 31 m
- 01Long-password DoS attack · Hacker101 CTF · Micro CMS v11:09:57
- 02Directory traversal attacks · Hacker101 · Petshop Pro1:20:50
₹699
All 10 modules · lifetime access