Back close

Course Detail

Course Name Web Application Security and Penetration Testing
Course Code 26SN643
Program M. Tech. in Cyber Security Systems & Networks
Credits 3
Campus Amritapuri

Syllabus

Syllabus

Principles of passive and active reconnaissance, attack surface concepts, Google Dorking, WHOIS, DNS records, certificate transparency, Shodan and Censys for internet-exposed service discovery, GitHub dorking for leaked credentials, theHarvester for automated enumeration. Web technology fingerprinting using Wappalyzer, WhatWeb, and BuildWith. Port and service scanning — TCP/UDP fundamentals, SYN and Connect scans, Nmap host discovery, version detection, OS fingerprinting, and NSE scripts. Directory and subdomain enumeration using Gobuster and Ffuf; HTTP response code interpretation; Httpx for HTTP probing. Burp Suite Community Edition — proxy setup, intercepting and modifying HTTP/S requests, Repeater, Spider, Decoder, Comparer, and Intruder.

SQL Injection — union-based, boolean-based blind, and time-based blind techniques; SQLMap for automated exploitation; NoSQL injection and MongoDB operator abuse. OS command injection using chaining operators; blind injection via time delays and out-of-band callbacks; common vulnerable sinks in PHP, Python, and Java. File upload vulnerabilities — MIME spoofing, double extensions, null bytes, PHP/JSP webshells, Local File Inclusion, Remote File Inclusion, and path traversal. Server-Side Template Injection (SSTI) in Jinja2 and Twig; escalation to Remote Code Execution. Exploit-DB, Metasploit framework — workspace setup, module search, configuration and execution; msfvenom payload generation.

Cross-Site Scripting (XSS) — reflected, stored, and DOM-based; session cookie theft, phishing overlays, keylogging; filter bypass techniques. Cross-Site Request Forgery (CSRF) — crafting proof-of-concept forms; bypassing weak defences; SameSite cookie attribute. Server-Side Request Forgery (SSRF) — reaching localhost and cloud metadata endpoints (169.254.169.254); blind SSRF via out-of-band callbacks; internal service enumeration. Session management and authentication flaws — session hijacking, improper termination, secure cookie attributes, password brute-forcing with Hydra, password spraying, OAuth 2.0 misconfigurations. Prompt injection and Web LLM attacks — direct and indirect prompt injection, insecure output handling, PortSwigger Web LLM Attack labs, mitigations.

Automated vulnerability scanning using Nikto, Nuclei, and Nessus Essentials. Gaining access and shell stabilisation — reverse shells in Bash, Python, PHP, and Netcat; upgrading to stable TTY; file transfer methods; Metasploit meterpreter session management. Linux privilege escalation — manual enumeration checklist; LinPEAS; sudo attacks via GTFOBins; SUID binary abuse; password hunting; kernel exploits including Dirty Pipe and DirtyCow; scheduled task abuse; PATH hijacking; capabilities abuse.

Vulnerability scoring — CVE, NVD, CWE, CVSS v3.1 Base metrics, scoring using NVD calculator, translating scores to business impact. Writing penetration test reports — Executive Summary, Scope and Methodology, Findings, Appendix; finding format with title, severity, description, evidence, and remediation. Bug bounty and responsible disclosure — coordinated disclosure, clear bug bounty report writing, HackerOne and Bugcrowd platform norms. Rules of Engagement and ethics — written authorisation, RoE, NDAs, legal boundaries under IT Act 2000 (India) and CFAA (US).

Text Books / References
  1. The Web Application Hacker’s Handbook, 2nd Edition – Stuttard & Pinto
  2. Real World Bug Hunting: A Field Guide to Web Hacking – Peter Yaworski
  3. Pentest Book (Open Source) – https://pentestbook.six2dez.com/
  4. HackTricks (Open Source) – https://book.hacktricks.xyz/
  5. PortSwigger Web Security Academy (Free) – https://portswigger.net/web-security
  6. TryHackMe – https://tryhackme.com  |  HackTheBox – https://hackthebox.com
  7. OWASP Testing Guide v4.2 – https://owasp.org/www-project-web-security-testing-guide/

Introduction

This course provides students with a structured understanding of web application security and penetration testing methodologies. It covers the complete lifecycle of a penetration test engagement from reconnaissance and scanning through exploitation, post-exploitation, privilege escalation, and professional reporting. Students will use industry-standard open-source tools and practise on legal, hands-on lab platforms to develop skills directly applicable to real-world cybersecurity roles

Objectives and Outcomes

Course Objectives 

  1. To understand the fundamental principles of reconnaissance, scanning, and web application vulnerability assessment.
  2. To identify and exploit common server-side and client-side vulnerabilities including injection attacks, XSS, SSRF, CSRF, and authentication flaws.
  3. To perform post-exploitation activities and privilege escalation on compromised systems.
  4. To develop professional penetration testing reports applying CVSS scoring, responsible disclosure norms, and ethical standards.

Course Outcomes

COs Description Bloom’s Level
CO1 Perform reconnaissance, scanning, and enumeration on a target using standard open-source tools. Apply (BL3)
CO2 Identify and exploit common web application vulnerabilities including injection attacks, file upload flaws, XSS, SSRF, and CSRF. Apply (BL3)
CO3 Perform post-exploitation activities and escalate privileges on Linux systems using appropriate tools and techniques. Analyze (BL4)
CO4 Produce a professional penetration testing report and apply responsible disclosure and CVSS-based severity ratings. Evaluate (BL5)

Prerequisites

  • Networking Fundamentals
  • Operating Systems
  • Basic Linux CLI

Evaluation Pattern

CO-PO / PSO Mapping

COs PO1 PO2 PO3 PSO1 PSO2 PSO3 PSO4
CO1 3 3 3 2
CO2 3 3 3 3
CO3 3 3 3 3
CO4 3 3 3 3 3

Evaluation Pattern – 70:30

  • Midterm Exam – 40%
  • Lab Assignments & Case Study – 30%
  • End Semester Exam (Lab exam –practical)  – 30%

DISCLAIMER: The appearance of external links on this web site does not constitute endorsement by the School of Biotechnology/Amrita Vishwa Vidyapeetham or the information, products or services contained therein. For other than authorized activities, the Amrita Vishwa Vidyapeetham does not exercise any editorial control over the information you may find at these locations. These links are provided consistent with the stated purpose of this web site.

Admissions Apply Now