← Back to the catalogueWeb Application Security
Intermediate to Advanced
Level
Classroom . Online . Hybrid
Mode
Course overview
A web application security course teaching attack and defence side by side. Every vulnerability class is exploited in a lab application and then fixed in code, so learners leave able to both find and remediate. Coverage follows the current OWASP Top 10 with additional modules on APIs and authentication.
The course ends with a full assessment of a running application plus a remediation pull request.
Who it is for
- Web developers and tech leads
- Application security analysts
- QA and testing engineers
- Penetration testers
Prerequisites
HTML, HTTP and one server-side language. Basic database knowledge.
How it runs
Learn → Practise → Build → Experience → Demonstrate, ending in a capstone. Delivered by practitioners from the engineering bench, in Madurai, Coimbatore and online.
Final project
Assessment Report Plus Remediation Commit
Programme sheet
The printed sheet carries the full module breakdown, labs, project work and certification path. Fees, dates and formats for the next intake are confirmed by the education team on enquiry.
Learning outcomes
01
Read HTTP traffic and manipulate requests deliberately.
02
Exploit and fix injection vulnerabilities.
03
Test authentication, session and access control logic.
04
Assess API endpoints for authorisation flaws.
05
Identify insecure configuration and dependencies.
06
Apply secure coding patterns and framework defences.
07
Report and verify remediation of findings.
Module structure
8 modulesModule 01
HTTP and Tooling
Requests and responses . Proxy interception . Lab targets . Browser dev tools
Tools — Burp Suite, OWASP ZAP, Cookies and Headers
SQL injection . Parameterisation and fixes . NoSQL injection . Template injection
Module 03
Cross-Site Scripting
Reflected . DOM-based . Output encoding . Stored
Lab
XSS Chain and Fix . Content Security Policy
Module 04
Authentication and Sessions
Password storage . Session fixation . Password reset flows . MFA . JWT pitfalls . Rate limiting
IDOR . Business logic abuse . Vertical and horizontal escalation . Server-side enforcement
REST and GraphQL surfaces . Mass assignment . Excessive data exposure . Rate limits . API keys and scopes
Module 07
Configuration and Supply Chain
Security headers . File upload handling . Secrets in repos . Dependency scanning . SBOM
Tools — Snyk, Dependency-Check
Module 08
Secure Development
Threat modelling . Secure coding standards . SAST and DAST in Cl . Verification
Assessment & certification
Module assignments and labs
25%
Final project and review
40%
Learners who complete all modules, submit the final project and clear the review receive a course completion certificate from Kaizen Infinities Private Limited. Project work is documented for the learner's portfolio, and interview preparation is included in the closing sessions.
Career outcomes . Roles this programme prepares for
Application Security EngineerWeb Penetration TesterSecure Software DeveloperDevSecOps EngineerSecurity Code Reviewer