Web Security
OWASP, injections, XSS, broken auth — understanding attacks to build real defenses.
What you'll actually learn
Most web vulnerabilities come from the same handful of trust mistakes repeated in new forms — trusting input that came from a user, trusting a session that anyone could have hijacked, trusting a query built from unescaped strings. This track works through the real OWASP-category attacks (injection, XSS, broken authentication) not as a list to memorize, but as consequences of specific trust mistakes, so you can spot the mistake in code you didn't write yet.
What you'll be able to do
You'll attack a deliberately vulnerable application yourself — inject a query, hijack a session, break an auth flow — and then fix the actual code so the same attack stops working. Building the exploit first is what makes the fix real instead of cargo-culted; you'll know exactly what a defense is defending against.
Syllabus
Leads to
Frequently asked
Roughly 2 hours across 10 hands-on quests — you can go at your own pace and pick up exactly where you left off.
You should be comfortable with Data & Applications, Security: The Foundations, How the Web Works first — the skill tree unlocks Web Security once you've cleared those.
Yes — Web Security is fully available on the free tier, starting with a free first quest and no payment method required to sign up. Plus and Elite remove pacing limits but don't gate any of the Web Security curriculum behind a paywall.
Create a free account and begin your first quest — no card required.
Start free