Class Central is learner-supported. When you buy through links on our site, we may earn an affiliate commission.

Coursera

Web Security, Social Engineering & External Attacks

Packt via Coursera

Overview

Google, IBM & Meta Certificates – 40% Off
One plan covers every Professional Certificate on Coursera.
Unlock All Certificates
This course features Coursera Coach! A smarter way to learn with interactive, real-time conversations that help you test your knowledge, challenge assumptions, and deepen your understanding as you progress through the course. Take your web application security skills to the next level by exploring common vulnerabilities that affect modern websites and learning how security professionals assess them in controlled environments. Through practical demonstrations and hands-on labs, you'll develop the ability to identify, analyze, and understand exploitation techniques while strengthening your knowledge of secure web application testing. The course begins with PHP code injection and file upload vulnerabilities before progressing to OS command injection and Server Side Include (SSI) attacks. You'll configure tools such as Foxy Proxy and Commix while learning to investigate server-side weaknesses responsibly. You'll then examine directory traversal vulnerabilities using Dotdotpwn and understand how attackers access unauthorized files through insecure application design. As you advance, you'll explore Cross-Site Scripting (XSS), broken access control, Insecure Direct Object References (IDOR), Cross-Site Request Forgery (CSRF), and brute force attacks using realistic lab environments and industry-standard tools. The course concludes with an SQL crash course, covering database fundamentals, queries, filtering, and advanced techniques that prepare you for understanding SQL-related security testing in later learning. This course is designed for aspiring penetration testers, cybersecurity students, IT professionals, developers, and ethical hackers seeking practical web security experience. Learners should have a basic understanding of networking, Linux, and introductory web technologies. The course is Intermediate level. By the end of the course, you will be able to identify and assess common web application vulnerabilities, configure security testing tools, evaluate authentication and authorization flaws, understand SQL fundamentals, and perform structured web application security assessments within authorized testing environments.

Syllabus

  • Attacks On Users
    • In this module, we will focus on user-targeted attacks, showing you how ethical hackers exploit vulnerabilities in users’ systems. You'll explore powerful tools like msfvenom and FatRat for creating backdoors and maintaining stealthy, long-term access to compromised systems.
  • Social Engineering
    • In this module, we will dive into social engineering attacks and how they exploit human behavior. We’ll cover tools and strategies used by ethical hackers to manipulate targets, and discuss methods for preventing these attacks, including phishing and malware detection.
  • Social Media Security
    • In this module, we will emphasize the importance of securing social media accounts from cyber threats. We will explore phishing tactics on platforms like Instagram and provide strategies for defending against these attacks and securing your personal and corporate profiles.
  • Beef
    • In this module, we will introduce Beef, an essential tool for ethical hackers. We’ll guide you through its functionalities, demonstrating how to use it for web-based attacks like hooking targets and stealing passwords, and offer strategies for defending against these attacks.
  • External Network Attacks
    • In this module, we will focus on external network attacks and the methods used by ethical hackers to exploit remote systems. You will explore tunneling services, backdoors, and various penetration testing tools, equipping you to conduct effective network penetration tests.
  • Fake Game Website Attacks
    • In this module, we will explore the use of fake game websites for social engineering and web-based attacks. You’ll learn how to create these sites, integrate them with tools like Beef, and protect yourself from falling victim to these types of attacks.
  • Post Hacking Sessions
    • In this module, we will focus on the critical post-hacking steps necessary for managing access and gathering data from compromised systems. You will learn about Meterpreter sessions, keyloggers, and maintaining stealth for long-term control of compromised systems.
  • Hacker Methodology
    • In this module, we will introduce the hacker methodology, a step-by-step approach used in ethical hacking. You will learn how to conduct thorough assessments and understand the ethical framework that guides responsible penetration testing.
  • Website Reconnaissance
    • In this module, we will cover website reconnaissance techniques, focusing on gathering critical information through tools like Maltego and Netcraft. You will explore DNS, Whois, and subdomain analysis to identify vulnerabilities in web applications.
  • Website Pentesting
    • In this module, we will focus on website penetration testing, guiding you through techniques like exploiting code execution vulnerabilities and uploading malicious files. You will also learn how to execute reverse TCP commands and file inclusion attacks to compromise web servers.
  • Cross Site Scripting
    • In this module, we will explore Cross Site Scripting (XSS) attacks and demonstrate how they can be exploited in real-world scenarios. You will also learn best practices for preventing XSS vulnerabilities and protecting web applications from this common attack.

Taught by

Packt - Course Instructors

Reviews

Start your review of Web Security, Social Engineering & External Attacks

Never Stop Learning.

Get personalized course recommendations, track subjects and courses with reminders, and more.

Someone learning on their laptop while sitting on the floor.