← Back to the catalogue
Domain 05 . Security

Web Application Security

50
Hours of teaching
Intermediate to Advanced
Level
8
Modules
Classroom . Online . Hybrid
Mode
Course overview

A web application security course teaching attack and defence side by side. Every vulnerability class is exploited in a lab application and then fixed in code, so learners leave able to both find and remediate. Coverage follows the current OWASP Top 10 with additional modules on APIs and authentication.

The course ends with a full assessment of a running application plus a remediation pull request.

Who it is for
  • Web developers and tech leads
  • Application security analysts
  • QA and testing engineers
  • Penetration testers
Prerequisites
HTML, HTTP and one server-side language. Basic database knowledge.
How it runs
Learn → Practise → Build → Experience → Demonstrate, ending in a capstone. Delivered by practitioners from the engineering bench, in Madurai, Coimbatore and online.
Final project
Assessment Report Plus Remediation Commit

Programme sheet

The printed sheet carries the full module breakdown, labs, project work and certification path. Fees, dates and formats for the next intake are confirmed by the education team on enquiry.

Learning outcomes

01
Read HTTP traffic and manipulate requests deliberately.
02
Exploit and fix injection vulnerabilities.
03
Test authentication, session and access control logic.
04
Assess API endpoints for authorisation flaws.
05
Identify insecure configuration and dependencies.
06
Apply secure coding patterns and framework defences.
07
Report and verify remediation of findings.

Module structure

8 modules
Module 01

HTTP and Tooling

Requests and responses . Proxy interception . Lab targets . Browser dev tools
Tools — Burp Suite, OWASP ZAP, Cookies and Headers
Module 02

Injection

SQL injection . Parameterisation and fixes . NoSQL injection . Template injection
Lab
Exploit and Patch
Module 03

Cross-Site Scripting

Reflected . DOM-based . Output encoding . Stored
Lab
XSS Chain and Fix . Content Security Policy
Module 04

Authentication and Sessions

Password storage . Session fixation . Password reset flows . MFA . JWT pitfalls . Rate limiting
Module 05

Access Control

IDOR . Business logic abuse . Vertical and horizontal escalation . Server-side enforcement
Lab
Authorisation Testing
Module 06

API Security

REST and GraphQL surfaces . Mass assignment . Excessive data exposure . Rate limits . API keys and scopes
Module 07

Configuration and Supply Chain

Security headers . File upload handling . Secrets in repos . Dependency scanning . SBOM
Tools — Snyk, Dependency-Check
Module 08

Secure Development

Threat modelling . Secure coding standards . SAST and DAST in Cl . Verification

Assessment & certification

Module assignments and labs
25%
Internal assessments
15%
Mini projects
20%
Final project and review
40%

Learners who complete all modules, submit the final project and clear the review receive a course completion certificate from Kaizen Infinities Private Limited. Project work is documented for the learner's portfolio, and interview preparation is included in the closing sessions.

Career outcomes . Roles this programme prepares for
Application Security EngineerWeb Penetration TesterSecure Software DeveloperDevSecOps EngineerSecurity Code Reviewer
Enquire or apply →Programme sheet (PDF)Institutions can commission a cohort

Also in Security