Penetration Testing

Learn Penetration Testing Concepts with Hands-on Projects

Course Curriculum

1. Web Application Penetration Testing

A. Web Fundamentals

  • HTTP methods
  • Cookies, sessions, tokens
  • CORS
  • JWT

B. OWASP Top 10 Deep-Dive

1. Authentication Vulnerabilities

  • Broken auth
  • Bypass methods
  • 2FA bypass

2. Access Control Attacks

  • IDOR
  • Horizontal & vertical privilege escalation

3. Injection Attacks

  • SQL Injection (manual + tools)
  • NoSQL Injection
  • Command Injection
  • LDAP, XML Injection

4. Cross-Site Scripting (XSS)

  • Reflected, Stored, Blind
  • Cookie stealing
  • Payload building

5. SSRF

  • Blind SSRF
  • Cloud metadata exploitation

6. File Upload Attacks

  • Web shells
  • Filter bypass

7. Deserialization Vulnerabilities

8. Business Logic Vulnerabilities

9. LFI & RFI

10.  P4 Vulnerabilities

C. Tools & Automation

  • Burp Suite Pro / Community
  • FFUF / Gobuster
  • Dirsearch
  • SQLMap
  • XSStrike
  • Nuclei

2. API Penetration Testing

A. API Basics

  • REST, SOAP
  • HTTP verbs
  • JWT, OAuth2

B. API Enumeration

  • Swagger
  • Postman
  • API discovery using tools

C. API Vulnerabilities

  • Broken object level authorization (BOLA)
  • Broken auth
  • Mass assignment
  • Rate limit bypass
  • Injection in APIs

D. Real-world API attack labs

3. Network Penetration Testing

1. Information Gathering

  • Network mapping
  • Host discovery
  • Nmap advanced scanning

2. Enumeration Techniques

  • SMB, FTP, SSH, SNMP enumeration
  • NetBIOS, RPC enumeration

3. Exploitation

  • Exploiting Windows vulnerabilities
  • EternalBlue, MS17-010
  • Linux exploitation
  • Buffer overflow basics

4. Password Attacks

  • Hydra, Medusa
  • Cracking Windows hashes

5. Post-Exploitation

  • Privilege escalation (Windows & Linux)
  • Persistence methods
  • Credential dumping
  • Pass-the-hash attacks

4 - Android Penetration Testing

1. Introduction to Android Architecture

  • APK structure
  • Manifest file
  • Dalvik & ART

2. Static Analysis

  • Decompiling APKs
  • JADX, apktool
  • Code review basics

3. Dynamic Analysis

  • Using emulator
  • Frida basics
  • Burp Suite Android setup

4. Android Vulnerabilities

  • Insecure data storage
  • Hardcoded keys
  • WebView vulnerabilities
  • Unsafe authentication
  • Root detection bypass
  • SSL pinning bypass

5. API + Mobile combined attacks

Enroll in the Course
(As Limited Seats Available!)

INR 45,000/-

Incl. 18% GST
Duration:
4 Months
Fees:
INR 45,000/-
Instructor:
Sumit Jain
Time:
4:00 PM IST
Start Date:
February 2, 2026
Thank you! Your submission has been received!
Oops! Something went wrong while submitting the form.

Meet Your Mentor

Get to know the expert behind your learning journey. Our instructor brings years of real-world industry experience and a passion for teaching that makes every session practical, engaging, and impactful.

How Skill Horizon Works?

Register for Course

Don't miss out on the chance to elevate your knowledge and achieve your goals – secure your spot now by registering for our course!

Demo Sessions

Once you register - take the first step toward a journey of discovery and skill enhancement. Join our demo sessions and envision the possibilities!

Fee Payment

Once you are happy with the Demo – invest in your success by paying the course fee and stepping into a brighter future.

Register Now

Thank you! Your submission has been received!

Stay tuned for more information...

For any additional queries reach out to the support team
Contact us
Oops! Something went wrong while submitting the form.