Skip to content
The route
04

Offensive · stage 4 of 10

Core Web Attacks

The four that appear in almost every report: SQL injection by hand and with SQLMap, IDOR against a real API, JWT flaws, and cross-site request forgery — each one exploited in a lab before it is defended.

Intermediate5 sessions6 h 18 mSessions 23–27
Get full access · ₹699

This module is included — it is not sold on its own.

// Sessions in this module

2 sections · 5 sessions · 6 h 18 m

Injection and broken access control4 h 6 m
  1. 01SQL injection · Types of SQL · POST-based SQLi1:36:20
  2. 02SQL injection · GET-based SQLi · SQLMap1:06:27
  3. 03IDOR · API fundamentals · Hacker101 · Postbook challenges1:22:45
Tokens and forged requests2 h 13 m
  1. 01JWT · JWT authentication · JWT vulnerabilities · CTF challenges1:02:50
  2. 02Cross-Site Request Forgery (CSRF) · PortSwigger labs1:09:40

₹699

All 10 modules · lifetime access

Get access