Currently Empty: ৳ 0.00
13 মাসের কোর্স, 600+ প্রি রেকর্ডেড ক্লাস!!
দীর্ঘ ১৩ মাসের কোর্স | 600+ প্রি-রেকর্ডেড ক্লাস | OSCP লেভেলের প্রশিক্ষণ
বাংলা ভাষায় প্রথমবারের মতো এমন একটি পেনেট্রেশন টেস্টিং কোর্স, যা আপনাকে প্রফেশনাল পেনেট্রেশন টেস্টার হিসাবে ইন্ডাস্ট্রিতে কাজ করার উপযোগী করে গড়ে তুলবে ।
আমাদের লক্ষ্য শুধু সার্টিফিকেশন নয়, বরং একজন দক্ষ সাইবার সিকিউরিটি প্রফেশনাল তৈরি করা।
বাংলা ভাষায় প্রথমবারের মতো এমন একটি পেনেট্রেশন টেস্টিং কোর্স, যা আপনাকে প্রফেশনাল পেনেট্রেশন টেস্টার হিসাবে ইন্ডাস্ট্রিতে কাজ করার উপযোগী করে গড়ে তুলবে ।
আমাদের লক্ষ্য শুধু সার্টিফিকেশন নয়, বরং একজন দক্ষ সাইবার সিকিউরিটি প্রফেশনাল তৈরি করা।
কোর্সে প্রি রেকর্ডেড ক্লাস থাকবে। ভিডিওগুলো প্রতি সপ্তাহে মডিউল হিসাবে দেওয়া হবে। কোর্সের মাঝেই আপনি সাপোর্ট পাবেন কোর্স এর যেকোনো ক্লাস বিষয়ে যেকোনো সমস্যায় ডিসকাশন গ্রুপে পোস্ট করলে আমাদের Pentester প্যানেলের শিক্ষকরা আপনাকে সাহায্য করবে। সপ্তাহে একটি করে Problem Solving লাইভ সেশন হবে
ক্লাস রিলিজ হবে প্রতিদিন – রাত 10 টার পর! । সপ্তাহে 6 টা ক্লাস সিক্রেট টেলিগ্রাম চ্যানেলে আপলোড করা হবে। বাকী 1 দিন প্রাকটিস করবেন
⭕ 10 টা Exam নেওয়া হবে এবং টোটাল 10 টা Exam এ ৭০% মার্কস পেলে সার্টিফিকেট দেওয়া হবে।
⚠️Registration Deadline: March 30th, 2026
✅ক্লাস শুরু – 1st April, 2026
Device Requirement:
⭕ PC with 4/8 RAM
⭕ Storage HDD/ SSD – 125/250 GB
⭕ Tryhackme 1 month Subscription/Voucher
প্রতি দিন শেখার পিছনে Minimum 2 ঘন্টা সময় দিতে হবে, কারণ ৯০% Practical class থাকবে | Main Course Fee 40,000/- কিন্তু PTP এর 4th ব্যাচ এর জন্য কোর্স ফি নির্ধারণ করা হয়েছে 15,000/-
Penetration Testing For Professionals: আপনার স্বপ্ন পূরণের সোপান
- বাংলা ভাষায় প্রথমবারের মতো এমন একটি কোর্স, যা পুরোপুরি হাতে-কলমে শেখাবে কিভাবে একজন ইন্টারপ্রাইজ লেভেলের পেনেট্রেশন টেস্টার হওয়া যায়।
- OSCP/CPTS মানের প্রশিক্ষণ দিয়ে আমরা তৈরি করি পেশাদার সাইবার সিকিউরিটি এক্সপার্ট।
- হ্যান্ডস-অন ট্রেনিং এবং বাস্তব সমস্যা সমাধানের সক্ষমতা অর্জন করতে পারবেন এই কোর্সের মাধ্যমে।
কেন এই কোর্স আপনার জন্য BEST?
- সঠিকভাবে স্কোপিং থেকে শুরু করে পেনেট্রেশন টেস্টিংয়ের সব ধাপ শেখানো।
- প্রি-রেকর্ডেড ক্লাস এবং সাপ্তাহিক লাইভ সাপোর্ট সেশন।
- ইন্ডাস্ট্রি-স্ট্যান্ডার্ড টুলস ব্যবহার করে বাস্তবসম্মত চ্যালেঞ্জ মোকাবেলার সুযোগ।
- প্রফেশনাল রিপোর্ট রাইটিং এবং ক্লায়েন্ট প্রেজেন্টেশন শেখানোর মাধ্যমে আপনাকে প্রকৃত পেশাদার করে তোলা।
আপনি এইখানে সুযোগ পাবেন রিয়েল পেনটেস্টিং প্রজেক্টে কাজ করার যদি ইন্টারভিউ এ পাশ করতে পারেন । যেটি এই কোর্সকে অন্য সব কোর্স থেকে আলাদা করে । আপনি সার্টিফিকেট পেলেও ইন্ডাস্ট্রিতে কাজ পাবেন না যদি না আপনার রিয়েল ওয়ার্ল্ড এ কাজ করার এক্সপেরিয়েন্স থাকে
Disclaimer
The instructor is not linked to OFFSEC in any manner. The course is independently created to better prepare for the Enterprise Level Pentesting. As we have 4 years+ Experience in Pentesting & RED Teaming.
“Hacked by Himel” A ISO/IEC 27001 Certified Platform has a clear ethics in Cyber security world, we are working to ensure data security of all Companies, Organizations, Countries and Peoples’, we follow the Cyber Security Act 39, 2023 of Bangladesh Govt as well. So, if you have intension to learn un-ethics technical learning from us, then we are discouraging to you to join this course; honestly, besides, we are very strict to follow our ethical principles.
❣️For Any Query: https://t.me/hackedbyhimel
❣️Call Now: 01951045900
https://wa.me/+8801951045900
Course Content
Introduction to Penetration Testing & Methodologies
This module introduces the core concepts, processes, and methodologies of penetration testing. Learners will understand the purpose, benefits, types, strategies, and cost considerations of pentesting, along with the difference between automated and manual testing. The module also covers pentesting phases, methodologies, ethics, required qualifications, and associated risks, providing a solid foundation for real-world and professional penetration testing.
What is Penetration Testing
Benefits of Conducting Pentesting
Pentesting Service Delivery Model
ROI For Penetration Testing
Types of Penetration Assessment
Strategies of Penetration Testing
Penetration Testing Cost & Comprehensiveness
Automated and Manual Pentesting
Common Areas of Pentesting
Process of Penetration Testing
Phase of Penetration Testing
Penetration Testing Methodologies
When Should Penetration Testing Be Performed
Ethics of a Penetration Tester
Qualification of a Pentester
Risk Associated With Penetration testing
Laws and Regulations of Data Protection
Overview of key data protection regulations in Bangladesh, USA, Europe (GDPR), UK (UK GDPR), India (DPDP Act), and China (PIPL), focusing on legal compliance and ethical handling of data during penetration testing.
Data Protection Laws in Bangladesh
Data Protection Framework in the United States
European Data Protection Law (GDPR)
UK Data Protection Laws (UK GDPR & DPA)
India’s Digital Personal Data Protection Act (DPDP Act)
China’s Data Protection & Cybersecurity Laws (PIPL, CSL, DSL)
Penetration Testing Scope & Engagement
This module covers how to plan, scope, and formalize a penetration testing engagement. Learners will understand pre-engagement activities, RFP handling, scoping meetings, assessment types, testing strategies, in-scope and out-of-scope assets, deliverables, timelines, team staffing, cost estimation, and proposal submission, ensuring clear, legal, and effective pentest engagements.
Pre-engagement Activities
Proposal Submission to RFP
Pentesting Scoping Meeting
Sample Questionnaires about Pentest
Identify The Pentest Assessment types
Identify Testing Strategy
Identify the Areas of Infrastructure to test
Listing Test not to be performed
Determining Project Deliverables
Identify the Reports to Deliver after the Pentest
Specifying The test Duration
Project Team Staffing
Estimated Cost of Pentest Engagement
Submitting the Proposal
Brainstorming sessions with TMTT
Establishing Communication Lines
Initial Teleconference with TPC
Drafting a Timeline for Pentest Project
Frequency of meeting
Deciding the Time of Day for pentest
Identify Personnel for Assistance
Signing ROE Documents
Engagement Letter from Client
Handling Legal Issues in Pentesting
This module explains how to manage legal risks in penetration testing engagements. Learners will understand the importance of legal counsel, pentesting contracts, authorization documents (Get-Out-of-Jail-Free letter), confidentiality/NDA clauses, legal vetting of engagement letters, and team independence checks, ensuring pentests are conducted lawfully, ethically, and safely.
Hiring A lawyer
Pentesting Contract Issued By Lawyer
Create a GET-of-Jail-free Card
Signing C/NDA Clauses
Having the E.L Vetted By A Lawyer
Independence Check of Team Members
Preparation For the Pentest
This module focuses on final preparation steps before executing a penetration test. Learners will cover reviewing the engagement letter, maintaining engagement logs, conducting kickoff meetings, preparing the SOW, obtaining required legal and client permissions, onsite coordination, and mission briefings, ensuring the pentest starts organized, authorized, and risk-free.
Review The Engagement Letter
Creating An Engagement Log
Kickoff Meeting
Preparing A Statement Of Work (SOW)
Obtain Special Permission From Law Enforcement Agency
Obtaining Temporary IC from Client
Visiting Client Organization’s Premises
Mission Briefing to Pentest Teams
Handling Scope Creeping During Pentesting
Professional Open-Source Intelligence (OSINT)
This module provides a comprehensive, hands-on approach to OSINT for penetration testing and investigations. Learners will gather intelligence using web, DNS, search engines, social media, email, images, business, wireless, and people-based OSINT, leveraging both manual techniques and automation tools. The module also covers sock puppets, note-keeping, lab building, real-world case studies, and OSINT report writing, enabling students to collect, analyze, and present actionable intelligence professionally.
Introduction to OSINT
Lets Create a Sock Puppet
Become Invisible when doing OSINT
Search Engine OSINT: Advanced Google Dorks
Search Engine OSINT: Advanced Bing
Search Engine OSINT: International Search Engine
Search Engine OSINT: Advanced 2lingual
Search Engine OSINT: Google Translator
Search Engine OSINT: Newspaper Archive
Search Engine OSINT: DuckDuckGo
Search Engine OSINT: StartPage
Search Engine OSINT: Qwant
Search Engine OSINT: Ahmia
Search Engine OSINT: TorLink
Search Engine OSINT: OnionlandSearch
Search Engine OSINT: FaganFinder
Search Engine OSINT: SearchEngineColossus
Search Engine OSINT: IntelTechniquesSearchEnginesTool
Search Engine OSINT: ArtificialIntelligence (A.I.)Engines
Image OSINT: Reverse Image Search
Image OSINT: Facial Recognition & People Search
Image OSINT: Car Model Identifier
Image OSINT: Social Media Image Analysis
Image OSINT: Metadata & Exif Data Analysis
Image OSINT: Image Manipulation & Enhancement
Image OSINT: AI-Generated Image & Deepfake Detection
Image OSINT: Identifying Geographical Locations 1 & 2 Task
Image OSINT: Identifying Geographical Locations 3 & 4 Task
Image OSINT: Practice Image OSINT With Geogussr.com
Email OSINT: Email Verification & Validation
Email OSINT: Email Format & Assumptions
Email OSINT: Gravatar & Profile Lookupsk
Practical Password OSINT
Email OSINT: Domain & Email Provider Analysis
Email OSINT: WhoXY Reverse WHOIS
Email OSINT: AnalyzeID
Email OSINT: MXToolbox
Email OSINT: OSINT Rocks
Username OSINT
People OSINT: True People Search
People OSINT: Fast People Search
People OSINT: Nuwber
People OSINT: Open Data USA
People OSINT: Intelius
People OSINT: Advanced Background Checks
People OSINT: Radaris
People OSINT: That’s Them & Spokeo
People OSINT: Webmii
People OSINT: Social Searcher & Truth Finder
People OSINT: People By Name & White Pages
People OSINT: Clustr Maps & Rocket Reach
People OSINT: Addresses & Classmates
People OSINT: Resumes & Indeed
People OSINT: Gift Registries
Phone Number OSINT
Social Network OSINT: Facebook osint
Social Network OSINT: With geotweetspy
Social Network OSINT: Tweeter(X) osint
Social Network OSINT: OldTweetDeck
Social Network OSINT: Instagram OSINT
OSINT Methodology & Workflow
Documentation & Reporting
Professional FootPrinting
This module focuses on professional footprinting and enumeration techniques used during the early stages of penetration testing. Learners will understand enumeration principles and methodologies while gathering detailed intelligence about domains, cloud resources, staff, and network services. The module covers hands‑on enumeration of common protocols and services such as FTP, Telnet, NTP, SNMP, SMB, NFS, DNS, SMTP, IMAP/POP3, MySQL, MSSQL, along with Linux and Windows remote management protocols, enabling accurate attack surface mapping for advanced exploitation.
Enumeration Principles
Enumeration Methodology
FTP Enumeration
Telnet Enumeration
NTP Enumeration
SNMP Enumeration
SMB Enumeration
NFS Enumeration
DNS Enumeration
SMTP Enumeration
IMAP / POP3 Enumeration
SNMP Enumeration
MySQL Enumeration
MSSQL Enumeration
Linux Remote Management Protocols
Windows Remote Management Protocol
Professional Vulnerability Assessment
This module introduces learners to systematic vulnerability assessment and scanning. It covers assessment standards, CVSS scoring, and CVE tracking, along with practical guidance on using leading tools like Nessus and OpenVAS. Students will learn how to configure scans, interpret results, handle scanning issues, and export findings, building the skills needed to identify and prioritize vulnerabilities in professional penetration testing engagements
Vulnerability Assessment
Assessment Standards
Vulnerability Assessment VS Penetration Testing
Common Vulnerability Scoring System (CVSS)
Common Vulnerabilities and Exposures (CVE)
Vulnerability Scanning Overview
Getting Started with Nessus
Nessus Scan All Types
Advanced Dynamic Scan ( Specific CVE Testing)
Advanced Scan (Specific Plugin & Compliance)
Authenticated Malware Assessment
Get A Backdoor Connection Assessment
Nessuss Credentialed Patch Audit
Custom Policy Template Create
Nessuss Active Directory Starter Scan
Find AI Assessment With Nessuss
Plugin Rules Setup Nessuss
Vulnerability Assessment Using OpenVas
Make Vulnerability Assessment Report For Clients
Network Penetration Testing – External
This module covers end‑to‑end external network penetration testing from initial planning to final reporting.
Objective of External Penetration Testing
External Pentesting Checklist
Scope Verification of Customer
ROE For External Pentesting
Client Communication During Pentesting
Myth Vs Reality of External Pentesting
Login Portal Attack Strategy
Password Spray On Microsoft 365 with Trevorspray
Password Spray On Outlook Web App
Attacking Other Portals
Bypassing MFA After Password Spraying Attack
Escalating Privilege After Gaining Initial Access
Bypassing MFA with 3 Common Methods
2FA Bypass Using Logic Flaw
MFA Bypass Using Burp Macro
External Pentesting Common findings and reports part 1
Common Findings Insufficient Patching
Common Findings Insecure Information Disclosure
Common Findings Info Disclosure Part 2
Final Session of the EPT Series (but not the last session overall)
Modern Internal Network Pentesting
This module provides a deep, hands-on understanding of Active Directory in internal network penetration testing. Learners will build realistic AD labs, understand authentication mechanisms (NTLM, Kerberos), and perform enumeration, credential harvesting, lateral movement, pivoting, exploitation, persistence, and privilege escalation using real-world techniques and tools. The module concludes with Active Directory hardening strategies, preparing learners to both attack and secure enterprise Windows environments professionally.
Intro to Internal Network Pentesting
Fundamentals of AD Part 1
Fundamentals of AD 1.2
How to Manage Users in AD
Managing Computers & Group Policy Object in AD
AD Authentication Methods: Karberos & NetNTLM
Trees, Forest, and Trust Relationship in Active Directory
How to Setup Windows Server
AD Domain Controller Setup
Create GPO for our AD Lab
How to Setup Windows victim Workstation for AD
Pre-Engagement & Attacks Surface Briefing
Identifying Hosts – Passive Host Identification
Active Validation & Service Enumeration of AD
Enumerating Users of AD with Kerbrute
Enumerate AD Users with Netexec
ldapsearch for AD Enum
Ldap Enumeration & Ldapdomdump for mapping AD
Gaining Initial Foothold on Active Directory: Breaching AD lab Setup
Practical LLMNR/NBTNS Poisoning Attacks on AD (Kali)
Practical As-Rep Roasting Using impact-GetNpUser
Practical Internal Password Spraying Attack on AD
Practical Netntlm password spray Attack
Practical SMB Relay Attack
Practical LDAP Pass-Back attack
Practical PXE Boot Password Scraping Attack on AD
Practical IPV6 Poisoning Attack
AD Enumeration After Gaining Initial Foothold
Introuction to AD Enumeration & Lab Seutp
Practical Credential Injection
AD Enumeration Using Microsoft Management Console (MMC)
AD Enumeration Using Command Prompt
AD Enumeration Using Powershell (RSAT)
Bloodhound community edition install and setup
AD Enumeration Using Bloodhoud CE part 1
AD Enumeration Using Bloodhoud CE part 2
AD Enumeration Using Powerview
Active Directory Lateral Movements
Introduction to Lateral Movements
Pass the Hash Attack Practical
Silver Ticket Attack Practical
Over The Hash Attack Practical
Active Directory Attacks – Pass the Hash
Windows RCE with PSEec & WMIC
Practical Lateral Movements with Mimikatz
Practical Lateral Movements Abusing User Behavior
Practical Pass the Ticket
Active Directory Pivoting
Introduction to Pivoting and Port Redirection
Introduction to Chisel
Practical Pivoting With Socat
Practical Pivoting With Chisel
Practical Pivoting With Chisel And SOCKS
Practical Tunneling Complex Exploitation
Active Directory Exploitation
Practical Exploiting Kerberos Permission Delegation
Practical Exploiting Automated Relays
Practical Exploiting AD Users
Practical Exploiting Group Policy Objects (GPOs)
Active Directory Persistence
Practical Active Directory Attacks – Golden Ticket
Introduction to Persistence
Practical Persistence with Credentials
Practical Persistence with DCSync
Practical Abusing GPOs for Persistence
Active Directory Credential Harvesting
Cached Credential Retrieval
Practical Extracting Credentials From Common Windows Locations
Practical Extracting Local Windows Credentials
Practical Extracting Creds From LSASS
Practical Windows Credential Manager
Practical Extracting Creds From Domain Controller
Practical Local Administrator Password Solution (LAPS)
Active Directory Hardening
Securing Authentication Methods
Implementing Least privilege Model
Microsoft Security Complience Toolkit
Protecting Against Known Attacks
Windows AD Hardening Cheatsheet
File Transfer During Assessment
Linux File Transfers
Windows File Transfer
Port Forwarding, Pivoting & Tunnelling
Introduction to Pivoting & Port Forwarding
SSH Local Port Forwarding
SSH Remote Port Forwarding
SSH Dynamic Port Forwarding
Introduction to Chisel
Pivoting Using Socat Tool
Pivoting Using Chisel Tool
Pivoting Using Socat & SOCKS
Tunneling Complex Exploits
Network Penetration Testing – Perimeter Devices
This module focuses on testing and bypassing perimeter security controls such as firewalls and IDS. Learners will assess firewall configurations, ACLs, detection capabilities, and vulnerabilities using practical techniques including traceroute, hping, nmap, and Nessus. The module also covers IDS evasion and bypass techniques, such as spoofing, flooding, traffic replay, and anonymity methods, enabling students to evaluate and report the effectiveness of enterprise perimeter defenses.
Assessing Firewall Security Implementation
Testing Firewall from Both Sides
Locate The Firewall with Traceroute
Try to pass through Firewall using Hping
Enumerate Firewall Access Control List using nmap
Map Firewall Make & Vulnerabilities
Bypass Firewall with Different Techniques
Assessing IDS Security Implementation
Common evading techniques to test IDS
Test IDS by Sending ARP Flood
Test IDS by MAC Spoofing
Test IDS by IP Spoofing
Test IDS by SYN Flood
Test IDS by Editing & Replaying Capture Network
Test IDS For DOS Attack
Test IDS for Bypassing with Anonymous Surfing Sites
Bypass IDS with Different Techniques
Hardening Perimeter Devices
Bug Bounty For Professional
This module teaches end-to-end web application bug bounty hunting, covering recon, enumeration, content discovery, vulnerability exploitation, WAF evasion, and professional reporting, preparing learners for real-world web security assessments.
Introduction to BBP
Importance of Web Application Security
Web Application Security Standards and Best Practices
Bug Bounty Hunting vs Penetration Testing
Phases of a Web Application Penetration Test
Understanding Scope, Ethics, Code of Conduct, etc.
Common Scoping Mistakes
Web Application Technologies Fundamentals
Reconnaissance and Information Gathering
Fingerprinting Web Technologies
Directory Enumeration and Brute Forcing
Burp Suite for Bug Hunter
Domain Discovery Part 1
Domain Discovery Part 2
Domain Discovery Part 3
Subdomain Enumeration using Subfinder
Subfinder: Configuring API
Subdomain Enumeration using AMASS
Subdomain Bruteforcing: FFuF
Subdomain Bruteforcing: GoBuster
Subdomain Bruteforcing: AMASS
Subdomain Bruteforcing: PureDNS
VHOST Enumeration Secrets
Filtering Live Domains/Subdomains
Subdomain Enumeration with Permutation #1
Subdomain Enumeration with Permutation #2
Finding Origin IP Address Part 1
Finding Origin IP Address Part 2
Content Discovery with Dirsearch
Recursive Content Enumeration
Content Discovery with FFUF like a pro!
Discovering Content Like a Pro
Introduction to Passive Enumeration
Passive Enumeration Using GetAllUrls
Passive Enumeration Using WayBackURLs
Passive Enumeration Using Combining Tools
Active Scanning Using Katana
How to Choose Right Wordlist for Target
Authentication and Authorization Attacks
Brute-force Attacks
Attacking MFA
IDOR – Insecure Direct Object Reference Attacks
Broken Access Control Attack
Testing a Website with Autorize
File Inclusion Vulnerabilities
Local File Inclusion (LFI) Attack
Remote File Inclusion (RFI) Attacks
File Inclusion Challenge Walkthrough
SQL Injection
Basic SQL Injection Attacks
Blind SQL Injection Attack
Time Based SQL Injection Attack
Second Order SQL Injection Attack
Cross-Site Scripting (XSS) Attack
Basic XSS Attacks
Stored XSS Attack
Dom-Based XSS Attacks
Command Injection Attacks
Blind Command Injection Attacks
Server-Side Template Injection (SSTI) Attack
XML External Entity (XXE) Injection Attacks
Insecure File Upload Client-Side Controls Bypass
Insecure File Upload Bypasses
Automated Scanners For Findings Bugs
Other Common Vulnerabilities
Cross-Site Request Forgery (CSRF) Attacks
Cross-Site Request Forgery (CSRF) Token Bypass
Server-Side Request Forgery (SSRF) Attacks
Blind Server-Side Request Forgery (SSRF)
Introduction to Subdomain Takeovers
Open Redirects Attacks
CMS Bug Hunting (WordPress)
WordPress User Enumeration
WordPress Core Version Enumeration
Wpscan Enumeration overview
Exploiting WordPress in Different Ways
Evasion Techniques During Bug Hunting
WAF Identification and Fingerprinting
Bypassing Input Validation and Encoding Techniques and many mores
Writing Effective Bug Hunting Report
Vulnerability Reporting and Disclosure (VDP)
How to Pick Bug Bounty Programs
You are Ready For Bug Hunting.. Start now
Web Application Penetration Testing (Advanced)
This module provides a complete, professional approach to web application penetration testing, covering pre-engagement, server-side, client-side, and advanced testing techniques. Learners will identify and exploit modern web vulnerabilities, including authentication, authorization, session management, injection flaws, business logic issues, API and advanced attack vectors, using real-world labs and scenarios to prepare for enterprise-grade web pentesting engagements.
Pre-Engagement of Web App Pentesting
Non-Disclosure Agreements of Web Pentesting
Rules of engagement of Web Pentesting
Goals of Web App Pentesting
Scope of Web App Pentesting
Time estimation of Web App Pentesting
Information gathering
Conduct Search Engine Discovery and Reconnaissance for Information Leakage
Fingerprint Web Server
Review Webpage Comments and Metadata for Information Leakage
Fingerprint Web Application Framework
Configuration and Deploy Management Testing
Test Network Infrastructure Configuration
Testing for Content Security Policy
Test File Extensions Handling for Sensitive Information
Review Old Backup and Unreferenced Files for Sensitive Information
Enumerate Infrastructure and Application Admin Interfaces
Test HTTP Methods
Test HTTP Strict Transport Security
Test RIA Cross Domain Policy
Test File Permission
Identity Management Testing
Test Role Definitions
Test User Registration Process
Test Account Provisioning Process
Testing for Account Enumeration and Guessable User Account
Testing for Weak or unenforced username policy
Test Permissions of Guest/Training Accounts
Test Account Suspension/Resumption Process
Authentication Testing
Testing for default credentials
Testing for Weak lock out mechanism
Testing for bypassing authentication schema
Test remember password functionality
Testing for Browser cache weakness
Testing for Weak password policy
Testing for Weak security question/answer
Testing for weak password change or reset functionalities
Testing for Weaker authentication in alternative channel
Authorization Testing
Testing Directory traversal/file include
Testing for bypassing authorization schema
Testing for Privilege Escalation
Testing for Insecure Direct Object References
Data Validation Testing
Testing for Reflected Cross Site Scripting
Testing for Stored Cross Site Scripting
Testing for HTTP Verb Tampering
Testing for HTTP Parameter pollution
Testing for SQL Injection
Testing for NoSQL injection
Testing for LDAP Injection
Testing for ORM Injection
Testing for XML Injection
Testing for SSI Injection
Testing for XPath Injection
Testing for Code Injection
Testing for Local File Inclusion
Testing for Remote File Inclusion
Testing for Command Injection
Testing for HTTP Splitting/Smuggling
Business logic Testing
Test Business Logic Data Validation
Test Ability to Forge Requests
Test Upload of Malicious Files
Client Side Testing
Testing for DOM based Cross Site Scripting
Testing for JavaScript Execution
Testing for HTML Injection
Testing for Client Side URL Redirect
Testing for CSS Injection
Testing for Client Side Resource Manipulation
Testing for Clickjacking
SQL injection vulnerability in WHERE clause allowing retrieval of hidden data
SQL injection vulnerability allowing login bypass
SQL injection attack, querying the database type and version on Oracle
SQL injection attack, querying the database type and version on MySQL and Microsoft
SQL injection attack, listing the database contents on Oracle
SQL injection UNION attack, determining the number of columns returned by the query
Blind SQL injection with conditional responses
Blind SQL injection with conditional errors
Visible error-based SQL injection
Blind SQL injection with time delays
Blind SQL injection with out-of-band interaction
Blind SQL injection with out-of-band data exfiltration
SQL injection with filter bypass via XML encoding
Reflected XSS into HTML context with nothing encoded
Stored XSS into HTML context with nothing encoded
DOM XSS in document.write sink using source location.search
DOM XSS in innerHTML sink using source location.search
Reflected XSS into attribute with angle brackets HTML-encoded
Stored XSS into anchor href attribute with double quotes HTML-encoded
DOM XSS in document.write sink using source location.search inside a select element
Reflected DOM XSS
Stored DOM XSS
Reflected XSS into HTML context with most tags and attributes blocked
Reflected XSS in canonical link tag
Exploiting cross-site scripting to steal cookies
Exploiting cross-site scripting to capture passwords
Exploiting XSS to perform CSRF
Reflected XSS with AngularJS sandbox escape without strings
Reflected XSS with AngularJS sandbox escape and CSP
Reflected XSS with event handlers and href attributes blocked
Reflected XSS in a JavaScript URL with some characters blocked
Reflected XSS protected by CSP, with CSP bypass
Reflected XSS protected by very strict CSP, with dangling markup attack
CSRF vulnerability with no defenses
CSRF where token validation depends on request method
CSRF where token validation depends on token being present
CSRF where token is not tied to user session
CSRF where token is tied to non-session cookie
CSRF where token is duplicated in cookie
SameSite Lax bypass via method override
SameSite Strict bypass via client-side redirect
SameSite Strict bypass via sibling domain
SameSite Lax bypass via cookie refresh
CSRF where Referer validation depends on header being present
Basic clickjacking with CSRF token protection
Clickjacking with form input data prefilled from a URL parameter
Clickjacking with a frame buster script
Exploiting clickjacking vulnerability to trigger DOM-based XSS
DOM XSS using web messages
DOM XSS using web messages and a JavaScript URL
DOM-based open redirection
DOM-based cookie manipulation
Exploiting DOM clobbering to enable XSS
Clobbering DOM attributes to bypass HTML filters
CORS vulnerability with basic origin reflection
CORS vulnerability with trusted null origin
CORS vulnerability with trusted insecure protocols
Exploiting XXE using external entities to retrieve files
Exploiting XXE to perform SSRF attacks
Blind XXE with out-of-band interaction
Blind XXE with out-of-band interaction via XML parameter entities
Exploiting blind XXE to exfiltrate data using a malicious external DTD
Exploiting blind XXE to retrieve data via error messages
Exploiting XInclude to retrieve files
Exploiting XXE via image file upload
Exploiting XXE to retrieve data by repurposing a local DTD
Basic SSRF against the local server
Basic SSRF against another back-end system
Blind SSRF with out-of-band detection
SSRF with filter bypass via open redirection vulnerability
Blind SSRF with Shellshock exploitation
SSRF with whitelist-based input filter
HTTP request smuggling, confirming a CL.TE vulnerability via differential responses
Exploiting HTTP request smuggling to reveal front-end request rewriting
Exploiting HTTP request smuggling to deliver reflected XSS
Response queue poisoning via H2.TE request smuggling
H2.CL request smuggling
HTTP/2 request smuggling via CRLF injection
HTTP/2 request splitting via CRLF injection
CL.0 request smuggling
HTTP request smuggling, obfuscating the TE header
Exploiting HTTP request smuggling to perform web cache poisoning
Bypassing access controls via HTTP/2 request tunnelling
Web cache poisoning via HTTP/2 request tunnelling
Client-side desync
Server-side pause-based request smuggling
Basic server-side template injection
Basic server-side template injection (code context)
Server-side template injection using documentation
Server-side template injection in a sandboxed environment
Server-side template injection with a custom exploit
File path traversal, simple case
File path traversal, traversal sequences blocked with absolute path bypass
File path traversal, traversal sequences stripped non-recursively
File path traversal, traversal sequences stripped with superfluous URL-decode
File path traversal, validation of file extension with null byte bypass
Unprotected admin functionality
Unprotected admin functionality with unpredictable URL
User role controlled by request parameter
User role can be modified in user profile
User ID controlled by request parameter
User ID controlled by request parameter, with unpredictable user IDs
User ID controlled by request parameter with data leakage in redirect
User ID controlled by request parameter with password disclosure
Insecure direct object references
URL-based access control can be circumvented
Multi-step process with no access control on one step
Referer-based access control
Username enumeration via different responses
Password reset broken logic
Username enumeration via subtly different responses
Username enumeration via response timing
Broken brute-force protection, IP block
Username enumeration via account lock
2FA broken logic
Brute-forcing a stay-logged-in cookie
Password reset poisoning via middleware
Password brute-force via password change
Broken brute-force protection, multiple credentials per request
2FA bypass using a brute-force attack
Manipulating WebSocket messages to exploit vulnerabilities
Cross-site WebSocket hijacking
Manipulating the WebSocket handshake to exploit vulnerabilities
Web cache poisoning with an unkeyed header
Web cache poisoning with an unkeyed cookie
Web cache poisoning with multiple headers
Targeted web cache poisoning using an unknown header
Web cache poisoning via an unkeyed query string
Web cache poisoning via a fat GET request
Web cache poisoning to exploit a DOM vulnerability via a cache with strict cacheability criteria
Combining web cache poisoning vulnerabilities
Internal cache poisoning
Modifying serialized objects
Modifying serialized data types
Using application functionality to exploit insecure deserialization
Arbitrary object injection in PHP
Exploiting Java deserialization with Apache Commons
Exploiting PHP deserialization with a pre-built gadget chain
Exploiting Ruby deserialization using a documented gadget chain
Developing a custom gadget chain for Java deserialization
Developing a custom gadget chain for PHP deserialization
Using PHAR deserialization to deploy a custom gadget chain
Information disclosure in error messages
Information disclosure on debug page
Source code disclosure via backup files
Authentication bypass via information disclosure
Information disclosure in version control history
Excessive trust in client-side controls
High-level logic vulnerability
Inconsistent security controls
Flawed enforcement of business rules
Low-level logic flaw
Inconsistent handling of exceptional input
Weak isolation on dual-use endpoint
Insufficient workflow validation
Authentication bypass via flawed state machine
Infinite money logic flaw
Authentication bypass via encryption oracle
Bypassing access controls using email address parsing discrepancies
Basic password reset poisoning
Host header authentication bypass
Web cache poisoning via ambiguous requests
Routing-based SSRF
SSRF via flawed request parsing
Host validation bypass via connection state attack
Password reset poisoning via dangling markup
Authentication bypass via OAuth implicit flow
SSRF via OpenID dynamic client registration
Forced OAuth profile linking
OAuth account hijacking via redirect_uri
Stealing OAuth access tokens via an open redirect
Stealing OAuth access tokens via a proxy page
Remote code execution via web shell upload
Web shell upload via Content-Type restriction bypass
Web shell upload via path traversal
Web shell upload via extension blacklist bypass
Web shell upload via obfuscated file extension
Remote code execution via polyglot web shell upload
Web shell upload via race condition
JWT authentication bypass via unverified signature
JWT authentication bypass via flawed signature verification
JWT authentication bypass via weak signing key
JWT authentication bypass via jwk header injection
JWT authentication bypass via jku header injection
JWT authentication bypass via kid header path traversal
JWT authentication bypass via algorithm confusion
JWT authentication bypass via algorithm confusion with no exposed key
Discovering vulnerabilities quickly with targeted scanning
Scanning non-standard data structures
Client-side prototype pollution via browser APIs
DOM XSS via client-side prototype pollution
DOM XSS via an alternative prototype pollution vector
Client-side prototype pollution via flawed sanitization
Client-side prototype pollution in third-party libraries
Privilege escalation via server-side prototype pollution
Detecting server-side prototype pollution without polluted property reflection
Bypassing flawed input filters for server-side prototype pollution
Remote code execution via server-side prototype pollution
Exfiltrating sensitive data via server-side prototype pollution
Accessing private GraphQL posts
Accidental exposure of private GraphQL fields
Finding a hidden GraphQL endpoint
Bypassing GraphQL brute force protections
Performing CSRF exploits over GraphQL
Limit overrun race conditions
Bypassing rate limits via race conditions
Multi-endpoint race conditions
Single-endpoint race conditions
Exploiting time-sensitive vulnerabilities
Partial construction race conditions
Detecting NoSQL injection
Exploiting NoSQL operator injection to bypass authentication
Exploiting NoSQL injection to extract data
Exploiting NoSQL operator injection to extract unknown fields
Exploiting LLM APIs with excessive agency
Exploiting vulnerabilities in LLM APIs
Indirect prompt injection
Exploiting insecure output handling in LLMs
Exploiting path mapping for web cache deception
Exploiting path delimiters for web cache deception
Exploiting exact-match cache rules for web cache deception
API Pentesting For Professional
This module delivers a hands-on, end-to-end approach to API security testing. Learners will understand API fundamentals, set up realistic labs, and perform reconnaissance, enumeration, and endpoint analysis. The module covers authentication and authorization flaws (BOLA, BFLA, JWT attacks), injection vulnerabilities, rate-limiting issues, mass assignment, excessive data exposure, SSRF, and vulnerability chaining, concluding with a final capstone challenge to simulate real-world API pentesting
Introduction to API Pentesting
Your Hacking Lab: Setup cRAPI
Your Hacking Lab: Setup VAPI
Introduction to Postman Tool
Introduction To Burpsuite
API Reconnaissance Passive
API Reconnaissance Active
Endpoint Analysis: Reverse Engineering an API
Reverse Engineering an API: Using APIs and Excessive Data Exposure
Scanning APIs: Finding Security Misconfiguration with ZAP
Enumerating APIs: Introduction to Enumeration
Enumerating APIs: Fuzzing APIs
Enumerating APIs: Discovery via Source Code
API Authorization Attacks: Introduction to Authorization
API Authorization Attacks: Broken Object Level Authorization (BOLA)
API Authorization Attacks: Broken Function Level Authorization
Classic Authentication Attacks
API Authentication Attacks: Introduction to Authentication
API Authentication Attacks: API Token Attacks
API Authentication Attacks: JSON Web Tokens (JWT): Attacking JWTs
Testing for Improper Assets Management: Improper Asset Management
API Injection: Introduction to Injection Attacks
API Injection: SQL Injection Lab
API Injection: SQL Injection Login Bypass
API Injection: NoSQL Injection Lab
Mass Assignment: Introduction to Mass Assignment
Testing Mass Assignment Attacks
Excessive Data Exposure: Introduction to Excessive Data Exposure
SSRF (Server-Side Request Forgery): Introduction to SSRF
Testing SSRF (Server-Side Request Forgery)
Evasion and Combining Techniques: Evasive Maneuvers
Chaining Vulnerabilities Command injection
Conclusion of API Pentesting
Linux Privilege Escalation
This module focuses on Linux enumeration and privilege escalation techniques used in real-world penetration testing. Learners will perform manual and automated enumeration, identify sensitive credentials and weak permissions, and exploit cron jobs, SUID/SGID binaries, and SUDO misconfigurations. The module also covers kernel exploitation, Linux capabilities abuse, service-level attacks (MySQL UDF), NFS exploitation, Docker escalation, and concludes with an advanced practical assessment, building strong hands-on Linux post-exploitation skills.
Introduction to Linux privilege Escalation
Intro to Enumeration
Manual Enumerations
Automatic Enumeration Techniques
Intro to Sensitive Credentials
Labs: Sensitive Credentials
Weak File Permissions & Exploitations
Introduction to Cron Jobs
Cron Exploitation: File Permissions
Cron Exploitation: PATH Manipulations
Cron Exploitation: Wild Cards
Intro to SUID/SGID
SUID Exploitation: Common Ways
SUID Exploitation: Environment Veriables
SUID Exploitation: Shared Objects
Intro to SUDO
SUDO Exploitation: Escape Sequences
SUDO Exploitation: Id_Perload
SUDO Exploitation: Id_Library_Path
Intro to Kernel Exploitation
Lab: Kernel Exploitation
Intro to Linux Capabilities
Capabilities Getcap Exploitation
Service Exploitation: MySQL User Defined Functions
Service Exploitation: MySQL User Defined Functions Labs
Intro to NFS
NFS Exploitation
Privilege Escalation with Docker
Conclusion of Linux Privilege Escalation
Windows Privilege Escalation
This module delivers a comprehensive, hands-on approach to Windows privilege escalation. Learners will perform manual and automated enumeration, understand UAC and Windows privilege architecture, and exploit service misconfigurations such as DLL hijacking, unquoted service paths, and weak permissions. The module covers credential harvesting, registry-based attacks, token impersonation techniques (RoguePotato, PrintSpoofer, JuicyPotato), and advanced exploits including kernel vulnerabilities, UAC bypasses, and insecure system components. It concludes with an advanced practical assessment, equipping learners with real-world Windows post-exploitation skills
Windows Enumeration: Automatic Enumeration
Windows Manual Enumeration
Windows User Access Control (UAC)
Windows Privilege Architectures
Abuse DLL Hijacking
Abuse Unquoted Service Paths
Abuse Weak Service Executable
Abuse Service Permissions
Privilege Escalation using Modern Web Services
Sensitive Credentials Exploitation
Sensitive Credentials Labs
Introduction to Windows Registry
Labs: Registry Attacks Elevated
Labs: Weak Registry Permissions
Labs: Registry Attacks Autorun
Introduction to Windows Privilege Escalation
Introduction to Token Impersonation Selmpersonate
Token Impersonation Selmpersonate RoguePotato
Token Impersonation Selmpersonate PrintSpoofer
Token Impersonation Selmpersonate PrintSpoofer
SeTakeOwnership Exploit
SetBackup Exploit
Insecure GUI Apps
Scheduled Tasks Exploitation
Startup Apps Exploitation
Vulnerable Software
Windows Kernel Exploitation
Windows UAC Bypass
Introduction to Kernel Exploitation
Conclusion of Windows Privilege Escalation
Documentation & Report Writing During Pentesting
Tags
A course by

Course Includes:
- Price:
৳ 40,000.00Original price was: ৳ 40,000.00.৳ 15,000.00Current price is: ৳ 15,000.00. - Instructor:mdhimelatikh
Lessons:754
- Level:Expert
৳ 15,000.00
৳ 40,000.00
Hi, Welcome back!




