Translated by Google
Practical Web Cybersecurity: Burp Suite, Broken Access Control, IDOR/ BOLA, and Bug Bounty for Beginners
From 28 C$ /h
This course is aimed at beginners and students who wish to understand web cybersecurity in a practical, progressive and structured way.
The goal is not to learn techniques by heart, but to understand how a web application works and how to reason when faced with a security problem.
We will be discussing, in particular:
• the basics of HTTP: requests, responses, methods, cookies and sessions;
• Authentication vs. Authorization;
• Getting started with Burp Suite Community;
• Broken Access Control;
• IDOR and BOLA;
• horizontal and vertical privilege escalation;
• roles, permissions and ownership;
• Security API basics;
• bug bounty methodology;
• drafting a clear vulnerability report.
The exercises are performed in dedicated learning labs, CTFs, or explicitly authorized environments.
My method is based on a simple line of reasoning:
Actor → Action → Object → Expected Authorization
Each session alternates between explanations, demonstrations, practical exercises with Burp Suite and guided correction.
The program can be adapted to the student's level, from the discovery of Web cybersecurity to the first methodologies of BAC/IDOR vulnerability research.
The goal is not to learn techniques by heart, but to understand how a web application works and how to reason when faced with a security problem.
We will be discussing, in particular:
• the basics of HTTP: requests, responses, methods, cookies and sessions;
• Authentication vs. Authorization;
• Getting started with Burp Suite Community;
• Broken Access Control;
• IDOR and BOLA;
• horizontal and vertical privilege escalation;
• roles, permissions and ownership;
• Security API basics;
• bug bounty methodology;
• drafting a clear vulnerability report.
The exercises are performed in dedicated learning labs, CTFs, or explicitly authorized environments.
My method is based on a simple line of reasoning:
Actor → Action → Object → Expected Authorization
Each session alternates between explanations, demonstrations, practical exercises with Burp Suite and guided correction.
The program can be adapted to the student's level, from the discovery of Web cybersecurity to the first methodologies of BAC/IDOR vulnerability research.
Extra information
For practical sessions, it is preferable to have a computer with an internet connection.
We will primarily use a web browser, Burp Suite Community and dedicated learning lab environments.
No prior experience in penetration testing or bug bounty programs is necessary. Basic computer skills are sufficient.
We will primarily use a web browser, Burp Suite Community and dedicated learning lab environments.
No prior experience in penetration testing or bug bounty programs is necessary. Basic computer skills are sufficient.
Location
Online from Morocco
Age
Teenagers (13-17 years old)
Adults (18-64 years old)
Seniors (65+ years old)
Student level
Beginner
Intermediate
Duration
60 minutes
90 minutes
The class is taught in
French
English
Arabic
Skills
Availability of a typical week
(GMT -04:00)
New York
Mon
Tue
Wed
Thu
Fri
Sat
Sun
00-04
04-08
08-12
12-16
16-20
20-24
Good-fit Instructor Guarantee