Overview
Exploit web application vulnerabilities using the same techniques real-world attackers deploy. Master the tools and methodologies for professional web application penetration testing through intensive hands-on practice.
Web applications remain the primary attack vector for data breaches. SEC542 teaches systematic web app testing using industry-standard tools and proven methodologies that uncover vulnerabilities automated scanners miss.
Execute comprehensive web application assessments:
Discovery and Analysis
- Map application functionality and attack surface
- Identify authentication and session management flaws
- Analyze client-side code for vulnerabilities
- Enumerate hidden content and functionality
Injection and Exploitation
- Execute SQL injection from detection through data extraction
- Perform cross-site scripting attacks and session hijacking
- Exploit XML external entity vulnerabilities
- Chain vulnerabilities for maximum impact
Advanced Techniques
- Bypass web application firewalls
- Attack API endpoints and microservices
- Exploit deserialization vulnerabilities
- Test OAuth and SSO implementations
Over 30 hands-on labs using Burp Suite, custom scripts, and specialized tools. Attack realistic applications with real vulnerabilities - no simulated or watered-down exercises.
Build a systematic testing methodology ensuring comprehensive coverage while meeting time constraints of real engagements.
Earn GIAC GWAPT certification (exam sold separately). 36 CPE credits across 6 intensive days.
Highlights
- Apply OWASP-based methodology to systematically test web applications. Exploit injection flaws, XSS, CSRF, SSRF, XXE, and deserialization vulnerabilities. Chain smaller issues into remote code execution and data theft.
- 35 hands-on labs using Burp Suite, ffuf, and custom scripts. Practice against realistic applications with real vulnerabilities including prototype pollution, Java deserialization, and file inclusion attacks.
- Prepares for GIAC GWAPT certification. Built for pen testers and security professionals conducting web application assessments. 6 days, 36 CPEs.
Details
Introducing multi-product solutions
You can now purchase comprehensive solutions tailored to use cases and industries.
Features and programs
Financing for AWS Marketplace purchases
Pricing
Dimension | Description | Cost/12 months |
|---|---|---|
SEC542 - Single User | Single user license for Offensive Ops - SEC542: Web App Pen Testing & Ethical Hacking | $8,780.00 |
Vendor refund policy
Refund requests must be submitted by the deadline date specific to User's training event. To find the specific deadline date for User's training event, please go to training event link at <www.sans.org > and click on the cancellations link.
How can we make this page better?
Legal
Vendor terms and conditions
Content disclaimer
Delivery details
Software as a Service (SaaS)
SaaS delivers cloud-based software applications directly to customers over the internet. You can access these applications through a subscription model. You will pay recurring monthly usage fees through your AWS bill, while AWS handles deployment and infrastructure management, ensuring scalability, reliability, and seamless integration with other AWS services.
Support
Vendor support
AWS infrastructure support
AWS Support is a one-on-one, fast-response support channel that is staffed 24x7x365 with experienced and technical support engineers. The service helps customers of all sizes and technical abilities to successfully utilize the products and features provided by Amazon Web Services.
Similar products
