Skip to content
The route
06

Offensive · stage 6 of 10

Advanced Web Exploitation

The eleven sessions that separate a scanner operator from a tester: authentication bypass and 2FA defeat, information disclosure, both HTTP request smuggling desyncs, business logic flaws, host header attacks and directory traversal.

Advanced11 sessions15 h 40 mSessions 49–52, 55–58, 61–63
Get full access · ₹699

This module is included — it is not sold on its own.

// Sessions in this module

4 sections · 11 sessions · 15 h 40 m

Authentication and information disclosure6 h 33 m
  1. 01Authentication vulnerabilities · PortSwigger labs1:44:12
  2. 02Authentication bypass · 2FA and 2FA bypass · Brute-forcing credentials1:36:04
  3. 03Information disclosure vulnerabilities1:46:20
  4. 04Information disclosure labs1:26:01
HTTP request smuggling3 h 7 m

Both desync variants, with the smuggler tool driven on screen.

  1. 01HTTP request smuggling · CL.TE · The smuggler tool1:32:46
  2. 02HTTP request smuggling · TE.CL · PortSwigger labs1:34:29
Business logic and host header attacks3 h 29 m
  1. 01Business logic flaws · Password reset vulnerabilities · PortSwigger labs1:29:53
  2. 02PortSwigger labs · Logical vulnerabilities39:18
  3. 03Host header attacks · PortSwigger labs1:19:55
Traversal, DoS and Hacker101 CTFs2 h 31 m
  1. 01Long-password DoS attack · Hacker101 CTF · Micro CMS v11:09:57
  2. 02Directory traversal attacks · Hacker101 · Petshop Pro1:20:50

₹699

All 10 modules · lifetime access

Get access