Skip to content
Hacked By HimelHacked By Himel
  • Category
    • AI Security
    • Blue Team
    • Bug Bounty
    • cloud security
    • Ethical Hacking
    • Fundamentals
    • Network Pentesting
    • OSINT
    • Pentesting
    • Pentesting AI
  • Home
  • Courses
  • Blog
  • Contact Us
    • About US
    • Contact Us
    • Dashboard
0

Currently Empty: ৳ 0.00

Continue shopping

Join for Free
Hacked By HimelHacked By Himel
  • Home
  • Courses
  • Blog
  • Contact Us
    • About US
    • Contact Us
    • Dashboard
  • Home
  • Course
  • Penetration Testing For Professionals

Penetration Testing For Professionals

  • By mdhimelatikh
  • Pentesting
Breadcrumb Abstract Shape
Breadcrumb Abstract Shape
Breadcrumb Abstract Shape
  • Course Info
  • Instructor
  • More
    • 13 মাসের কোর্স, 600+ প্রি রেকর্ডেড ক্লাস!! 
       
      দীর্ঘ ১৩ মাসের কোর্স | 600+ প্রি-রেকর্ডেড ক্লাস | OSCP লেভেলের প্রশিক্ষণ
      বাংলা ভাষায় প্রথমবারের মতো এমন একটি পেনেট্রেশন টেস্টিং কোর্স, যা আপনাকে প্রফেশনাল পেনেট্রেশন টেস্টার হিসাবে ইন্ডাস্ট্রিতে কাজ করার উপযোগী করে গড়ে তুলবে ।
      আমাদের লক্ষ্য শুধু সার্টিফিকেশন নয়, বরং একজন দক্ষ সাইবার সিকিউরিটি প্রফেশনাল তৈরি করা।
       
       কোর্সে  প্রি রেকর্ডেড ক্লাস থাকবে। ভিডিওগুলো প্রতি সপ্তাহে মডিউল হিসাবে দেওয়া হবে। কোর্সের মাঝেই আপনি সাপোর্ট পাবেন কোর্স এর যেকোনো ক্লাস বিষয়ে যেকোনো সমস্যায় ডিসকাশন গ্রুপে পোস্ট করলে আমাদের Pentester প্যানেলের শিক্ষকরা আপনাকে সাহায্য করবে। সপ্তাহে একটি করে Problem Solving লাইভ সেশন হবে
       
      ক্লাস রিলিজ হবে প্রতিদিন – রাত 10 টার পর! । সপ্তাহে 6 টা ক্লাস সিক্রেট টেলিগ্রাম চ্যানেলে আপলোড করা হবে। বাকী 1 দিন প্রাকটিস করবেন
       
      ⭕ 10 টা Exam নেওয়া হবে এবং টোটাল 10 টা Exam এ ৭০% মার্কস পেলে সার্টিফিকেট দেওয়া হবে।
       
      ⚠️Registration Deadline: March 30th, 2026
      ✅ক্লাস শুরু – 1st April, 2026
       
      Device Requirement: 
      ⭕ PC with 4/8 RAM 
      ⭕ Storage HDD/ SSD – 125/250 GB

      ⭕ Tryhackme 1 month Subscription/Voucher

      প্রতি দিন শেখার পিছনে Minimum 2 ঘন্টা সময় দিতে হবে, কারণ ৯০% Practical class থাকবে | Main Course Fee  40,000/-  কিন্তু PTP এর 4th ব্যাচ এর জন্য কোর্স ফি  নির্ধারণ করা হয়েছে 15,000/- 
       

      Penetration Testing For Professionals: আপনার স্বপ্ন পূরণের সোপান

      • বাংলা ভাষায় প্রথমবারের মতো এমন একটি কোর্স, যা পুরোপুরি হাতে-কলমে শেখাবে কিভাবে একজন ইন্টারপ্রাইজ লেভেলের পেনেট্রেশন টেস্টার হওয়া যায়।
      • OSCP/CPTS মানের প্রশিক্ষণ দিয়ে আমরা তৈরি করি পেশাদার সাইবার সিকিউরিটি এক্সপার্ট।
      • হ্যান্ডস-অন ট্রেনিং এবং বাস্তব সমস্যা সমাধানের সক্ষমতা অর্জন করতে পারবেন এই কোর্সের মাধ্যমে।
       

      কেন এই কোর্স আপনার জন্য BEST?

      • সঠিকভাবে স্কোপিং থেকে শুরু করে পেনেট্রেশন টেস্টিংয়ের সব ধাপ শেখানো।
      • প্রি-রেকর্ডেড ক্লাস এবং সাপ্তাহিক লাইভ সাপোর্ট সেশন।
      • ইন্ডাস্ট্রি-স্ট্যান্ডার্ড টুলস ব্যবহার করে বাস্তবসম্মত চ্যালেঞ্জ মোকাবেলার সুযোগ।
      • প্রফেশনাল রিপোর্ট রাইটিং এবং ক্লায়েন্ট প্রেজেন্টেশন শেখানোর মাধ্যমে আপনাকে প্রকৃত পেশাদার করে তোলা।
      আপনি এইখানে সুযোগ পাবেন রিয়েল পেনটেস্টিং প্রজেক্টে কাজ করার যদি ইন্টারভিউ এ পাশ করতে পারেন ।  যেটি এই কোর্সকে অন্য সব কোর্স থেকে আলাদা করে । আপনি সার্টিফিকেট পেলেও ইন্ডাস্ট্রিতে কাজ পাবেন না যদি না আপনার রিয়েল ওয়ার্ল্ড এ কাজ করার এক্সপেরিয়েন্স থাকে 
       
      Disclaimer

      The instructor is not linked to OFFSEC in any manner. The course is independently created to better prepare for the Enterprise Level Pentesting. As we have 4 years+ Experience in Pentesting & RED Teaming.

      “Hacked by Himel” A ISO/IEC 27001 Certified  Platform has a clear ethics in Cyber security world, we are working to ensure data security of all Companies, Organizations, Countries and Peoples’, we follow the Cyber Security Act 39, 2023 of Bangladesh Govt as well.  So, if you have intension to learn un-ethics technical learning from us, then we are discouraging to you to join this course; honestly, besides, we are very strict to follow our ethical principles. 

      ❣️For Any Query: https://t.me/hackedbyhimel

      ❣️Call Now: 01951045900
      https://wa.me/+8801951045900

       
      Show More

      Course Content

      Introduction to Penetration Testing & Methodologies
      This module introduces the core concepts, processes, and methodologies of penetration testing. Learners will understand the purpose, benefits, types, strategies, and cost considerations of pentesting, along with the difference between automated and manual testing. The module also covers pentesting phases, methodologies, ethics, required qualifications, and associated risks, providing a solid foundation for real-world and professional penetration testing.

      • What is Penetration Testing
      • Benefits of Conducting Pentesting
      • Pentesting Service Delivery Model
      • ROI For Penetration Testing
      • Types of Penetration Assessment
      • Strategies of Penetration Testing
      • Penetration Testing Cost & Comprehensiveness
      • Automated and Manual Pentesting
      • Common Areas of Pentesting
      • Process of Penetration Testing
      • Phase of Penetration Testing
      • Penetration Testing Methodologies
      • When Should Penetration Testing Be Performed
      • Ethics of a Penetration Tester
      • Qualification of a Pentester
      • Risk Associated With Penetration testing

      Laws and Regulations of Data Protection
      Overview of key data protection regulations in Bangladesh, USA, Europe (GDPR), UK (UK GDPR), India (DPDP Act), and China (PIPL), focusing on legal compliance and ethical handling of data during penetration testing.

      • Data Protection Laws in Bangladesh
      • Data Protection Framework in the United States
      • European Data Protection Law (GDPR)
      • UK Data Protection Laws (UK GDPR & DPA)
      • India’s Digital Personal Data Protection Act (DPDP Act)
      • China’s Data Protection & Cybersecurity Laws (PIPL, CSL, DSL)

      Penetration Testing Scope & Engagement
      This module covers how to plan, scope, and formalize a penetration testing engagement. Learners will understand pre-engagement activities, RFP handling, scoping meetings, assessment types, testing strategies, in-scope and out-of-scope assets, deliverables, timelines, team staffing, cost estimation, and proposal submission, ensuring clear, legal, and effective pentest engagements.

      • Pre-engagement Activities
      • Proposal Submission to RFP
      • Pentesting Scoping Meeting
      • Sample Questionnaires about Pentest
      • Identify The Pentest Assessment types
      • Identify Testing Strategy
      • Identify the Areas of Infrastructure to test
      • Listing Test not to be performed
      • Determining Project Deliverables
      • Identify the Reports to Deliver after the Pentest
      • Specifying The test Duration
      • Project Team Staffing
      • Estimated Cost of Pentest Engagement
      • Submitting the Proposal
      • Brainstorming sessions with TMTT
      • Establishing Communication Lines
      • Initial Teleconference with TPC
      • Drafting a Timeline for Pentest Project
      • Frequency of meeting
      • Deciding the Time of Day for pentest
      • Identify Personnel for Assistance
      • Signing ROE Documents
      • Engagement Letter from Client

      Handling Legal Issues in Pentesting
      This module explains how to manage legal risks in penetration testing engagements. Learners will understand the importance of legal counsel, pentesting contracts, authorization documents (Get-Out-of-Jail-Free letter), confidentiality/NDA clauses, legal vetting of engagement letters, and team independence checks, ensuring pentests are conducted lawfully, ethically, and safely.

      • Hiring A lawyer
      • Pentesting Contract Issued By Lawyer
      • Create a GET-of-Jail-free Card
      • Signing C/NDA Clauses
      • Having the E.L Vetted By A Lawyer
      • Independence Check of Team Members

      Preparation For the Pentest
      This module focuses on final preparation steps before executing a penetration test. Learners will cover reviewing the engagement letter, maintaining engagement logs, conducting kickoff meetings, preparing the SOW, obtaining required legal and client permissions, onsite coordination, and mission briefings, ensuring the pentest starts organized, authorized, and risk-free.

      • Review The Engagement Letter
      • Creating An Engagement Log
      • Kickoff Meeting
      • Preparing A Statement Of Work (SOW)
      • Obtain Special Permission From Law Enforcement Agency
      • Obtaining Temporary IC from Client
      • Visiting Client Organization’s Premises
      • Mission Briefing to Pentest Teams
      • Handling Scope Creeping During Pentesting

      Professional Open-Source Intelligence (OSINT)
      This module provides a comprehensive, hands-on approach to OSINT for penetration testing and investigations. Learners will gather intelligence using web, DNS, search engines, social media, email, images, business, wireless, and people-based OSINT, leveraging both manual techniques and automation tools. The module also covers sock puppets, note-keeping, lab building, real-world case studies, and OSINT report writing, enabling students to collect, analyze, and present actionable intelligence professionally.

      • Introduction to OSINT
      • Lets Create a Sock Puppet
      • Become Invisible when doing OSINT
      • Search Engine OSINT: Advanced Google Dorks
      • Search Engine OSINT: Advanced Bing
      • Search Engine OSINT: International Search Engine
      • Search Engine OSINT: Advanced 2lingual
      • Search Engine OSINT: Google Translator
      • Search Engine OSINT: Newspaper Archive
      • Search Engine OSINT: DuckDuckGo
      • Search Engine OSINT: StartPage
      • Search Engine OSINT: Qwant
      • Search Engine OSINT: Ahmia
      • Search Engine OSINT: TorLink
      • Search Engine OSINT: OnionlandSearch
      • Search Engine OSINT: FaganFinder
      • Search Engine OSINT: SearchEngineColossus
      • Search Engine OSINT: IntelTechniquesSearchEnginesTool
      • Search Engine OSINT: ArtificialIntelligence (A.I.)Engines
      • Image OSINT: Reverse Image Search
      • Image OSINT: Facial Recognition & People Search
      • Image OSINT: Car Model Identifier
      • Image OSINT: Social Media Image Analysis
      • Image OSINT: Metadata & Exif Data Analysis
      • Image OSINT: Image Manipulation & Enhancement
      • Image OSINT: AI-Generated Image & Deepfake Detection
      • Image OSINT: Identifying Geographical Locations 1 & 2 Task
      • Image OSINT: Identifying Geographical Locations 3 & 4 Task
      • Image OSINT: Practice Image OSINT With Geogussr.com
      • Email OSINT: Email Verification & Validation
      • Email OSINT: Email Format & Assumptions
      • Email OSINT: Gravatar & Profile Lookupsk
      • Practical Password OSINT
      • Email OSINT: Domain & Email Provider Analysis
      • Email OSINT: WhoXY Reverse WHOIS
      • Email OSINT: AnalyzeID
      • Email OSINT: MXToolbox
      • Email OSINT: OSINT Rocks
      • Username OSINT
      • People OSINT: True People Search
      • People OSINT: Fast People Search
      • People OSINT: Nuwber
      • People OSINT: Open Data USA
      • People OSINT: Intelius
      • People OSINT: Advanced Background Checks
      • People OSINT: Radaris
      • People OSINT: That’s Them & Spokeo
      • People OSINT: Webmii
      • People OSINT: Social Searcher & Truth Finder
      • People OSINT: People By Name & White Pages
      • People OSINT: Clustr Maps & Rocket Reach
      • People OSINT: Addresses & Classmates
      • People OSINT: Resumes & Indeed
      • People OSINT: Gift Registries
      • Phone Number OSINT
      • Social Network OSINT: Facebook osint
      • Social Network OSINT: With geotweetspy
      • Social Network OSINT: Tweeter(X) osint
      • Social Network OSINT: OldTweetDeck
      • Social Network OSINT: Instagram OSINT
      • OSINT Methodology & Workflow
      • Documentation & Reporting

      Professional FootPrinting
      This module focuses on professional footprinting and enumeration techniques used during the early stages of penetration testing. Learners will understand enumeration principles and methodologies while gathering detailed intelligence about domains, cloud resources, staff, and network services. The module covers hands‑on enumeration of common protocols and services such as FTP, Telnet, NTP, SNMP, SMB, NFS, DNS, SMTP, IMAP/POP3, MySQL, MSSQL, along with Linux and Windows remote management protocols, enabling accurate attack surface mapping for advanced exploitation.

      • Enumeration Principles
      • Enumeration Methodology
      • FTP Enumeration
      • Telnet Enumeration
      • NTP Enumeration
      • SNMP Enumeration
      • SMB Enumeration
      • NFS Enumeration
      • DNS Enumeration
      • SMTP Enumeration
      • IMAP / POP3 Enumeration
      • SNMP Enumeration
      • MySQL Enumeration
      • MSSQL Enumeration
      • Linux Remote Management Protocols
      • Windows Remote Management Protocol

      Professional Vulnerability Assessment
      This module introduces learners to systematic vulnerability assessment and scanning. It covers assessment standards, CVSS scoring, and CVE tracking, along with practical guidance on using leading tools like Nessus and OpenVAS. Students will learn how to configure scans, interpret results, handle scanning issues, and export findings, building the skills needed to identify and prioritize vulnerabilities in professional penetration testing engagements

      • Vulnerability Assessment
      • Assessment Standards
      • Vulnerability Assessment VS Penetration Testing
      • Common Vulnerability Scoring System (CVSS)
      • Common Vulnerabilities and Exposures (CVE)
      • Vulnerability Scanning Overview
      • Getting Started with Nessus
      • Nessus Scan All Types
      • Advanced Dynamic Scan ( Specific CVE Testing)
      • Advanced Scan (Specific Plugin & Compliance)
      • Authenticated Malware Assessment
      • Get A Backdoor Connection Assessment
      • Nessuss Credentialed Patch Audit
      • Custom Policy Template Create
      • Nessuss Active Directory Starter Scan
      • Find AI Assessment With Nessuss
      • Plugin Rules Setup Nessuss
      • Vulnerability Assessment Using OpenVas
      • Make Vulnerability Assessment Report For Clients

      Network Penetration Testing – External
      This module covers end‑to‑end external network penetration testing from initial planning to final reporting.

      • Objective of External Penetration Testing
      • External Pentesting Checklist
      • Scope Verification of Customer
      • ROE For External Pentesting
      • Client Communication During Pentesting
      • Myth Vs Reality of External Pentesting
      • Login Portal Attack Strategy
      • Password Spray On Microsoft 365 with Trevorspray
      • Password Spray On Outlook Web App
      • Attacking Other Portals
      • Bypassing MFA After Password Spraying Attack
      • Escalating Privilege After Gaining Initial Access
      • Bypassing MFA with 3 Common Methods
      • 2FA Bypass Using Logic Flaw
      • MFA Bypass Using Burp Macro
      • External Pentesting Common findings and reports part 1
      • Common Findings Insufficient Patching
      • Common Findings Insecure Information Disclosure
      • Common Findings Info Disclosure Part 2
      • Final Session of the EPT Series (but not the last session overall)

      Modern Internal Network Pentesting
      This module provides a deep, hands-on understanding of Active Directory in internal network penetration testing. Learners will build realistic AD labs, understand authentication mechanisms (NTLM, Kerberos), and perform enumeration, credential harvesting, lateral movement, pivoting, exploitation, persistence, and privilege escalation using real-world techniques and tools. The module concludes with Active Directory hardening strategies, preparing learners to both attack and secure enterprise Windows environments professionally.

      • Intro to Internal Network Pentesting
      • Fundamentals of AD Part 1
      • Fundamentals of AD 1.2
      • How to Manage Users in AD
      • Managing Computers & Group Policy Object in AD
      • AD Authentication Methods: Karberos & NetNTLM
      • Trees, Forest, and Trust Relationship in Active Directory
      • How to Setup Windows Server
      • AD Domain Controller Setup
      • Create GPO for our AD Lab
      • How to Setup Windows victim Workstation for AD
      • Pre-Engagement & Attacks Surface Briefing
      • Identifying Hosts – Passive Host Identification
      • Active Validation & Service Enumeration of AD
      • Enumerating Users of AD with Kerbrute
      • Enumerate AD Users with Netexec
      • ldapsearch for AD Enum
      • Ldap Enumeration & Ldapdomdump for mapping AD
      • Gaining Initial Foothold on Active Directory: Breaching AD lab Setup
      • Practical LLMNR/NBTNS Poisoning Attacks on AD (Kali)
      • Practical As-Rep Roasting Using impact-GetNpUser
      • Practical Internal Password Spraying Attack on AD
      • Practical Netntlm password spray Attack
      • Practical SMB Relay Attack
      • Practical LDAP Pass-Back attack
      • Practical PXE Boot Password Scraping Attack on AD
      • Practical IPV6 Poisoning Attack
      • AD Enumeration After Gaining Initial Foothold
      • Introuction to AD Enumeration & Lab Seutp
      • Practical Credential Injection
      • AD Enumeration Using Microsoft Management Console (MMC)
      • AD Enumeration Using Command Prompt
      • AD Enumeration Using Powershell (RSAT)
      • Bloodhound community edition install and setup
      • AD Enumeration Using Bloodhoud CE part 1
      • AD Enumeration Using Bloodhoud CE part 2
      • AD Enumeration Using Powerview
      • Active Directory Lateral Movements
      • Introduction to Lateral Movements
      • Pass the Hash Attack Practical
      • Silver Ticket Attack Practical
      • Over The Hash Attack Practical
      • Active Directory Attacks – Pass the Hash
      • Windows RCE with PSEec & WMIC
      • Practical Lateral Movements with Mimikatz
      • Practical Lateral Movements Abusing User Behavior
      • Practical Pass the Ticket
      • Active Directory Pivoting
      • Introduction to Pivoting and Port Redirection
      • Introduction to Chisel
      • Practical Pivoting With Socat
      • Practical Pivoting With Chisel
      • Practical Pivoting With Chisel And SOCKS
      • Practical Tunneling Complex Exploitation
      • Active Directory Exploitation
      • Practical Exploiting Kerberos Permission Delegation
      • Practical Exploiting Automated Relays
      • Practical Exploiting AD Users
      • Practical Exploiting Group Policy Objects (GPOs)
      • Active Directory Persistence
      • Practical Active Directory Attacks – Golden Ticket
      • Introduction to Persistence
      • Practical Persistence with Credentials
      • Practical Persistence with DCSync
      • Practical Abusing GPOs for Persistence
      • Active Directory Credential Harvesting
      • Cached Credential Retrieval
      • Practical Extracting Credentials From Common Windows Locations
      • Practical Extracting Local Windows Credentials
      • Practical Extracting Creds From LSASS
      • Practical Windows Credential Manager
      • Practical Extracting Creds From Domain Controller
      • Practical Local Administrator Password Solution (LAPS)
      • Active Directory Hardening
      • Securing Authentication Methods
      • Implementing Least privilege Model
      • Microsoft Security Complience Toolkit
      • Protecting Against Known Attacks
      • Windows AD Hardening Cheatsheet

      File Transfer During Assessment

      • Linux File Transfers
      • Windows File Transfer

      Port Forwarding, Pivoting & Tunnelling

      • Introduction to Pivoting & Port Forwarding
      • SSH Local Port Forwarding
      • SSH Remote Port Forwarding
      • SSH Dynamic Port Forwarding
      • Introduction to Chisel
      • Pivoting Using Socat Tool
      • Pivoting Using Chisel Tool
      • Pivoting Using Socat & SOCKS
      • Tunneling Complex Exploits

      Network Penetration Testing – Perimeter Devices
      This module focuses on testing and bypassing perimeter security controls such as firewalls and IDS. Learners will assess firewall configurations, ACLs, detection capabilities, and vulnerabilities using practical techniques including traceroute, hping, nmap, and Nessus. The module also covers IDS evasion and bypass techniques, such as spoofing, flooding, traffic replay, and anonymity methods, enabling students to evaluate and report the effectiveness of enterprise perimeter defenses.

      • Assessing Firewall Security Implementation
      • Testing Firewall from Both Sides
      • Locate The Firewall with Traceroute
      • Try to pass through Firewall using Hping
      • Enumerate Firewall Access Control List using nmap
      • Map Firewall Make & Vulnerabilities
      • Bypass Firewall with Different Techniques
      • Assessing IDS Security Implementation
      • Common evading techniques to test IDS
      • Test IDS by Sending ARP Flood
      • Test IDS by MAC Spoofing
      • Test IDS by IP Spoofing
      • Test IDS by SYN Flood
      • Test IDS by Editing & Replaying Capture Network
      • Test IDS For DOS Attack
      • Test IDS for Bypassing with Anonymous Surfing Sites
      • Bypass IDS with Different Techniques
      • Hardening Perimeter Devices

      Bug Bounty For Professional
      This module teaches end-to-end web application bug bounty hunting, covering recon, enumeration, content discovery, vulnerability exploitation, WAF evasion, and professional reporting, preparing learners for real-world web security assessments.

      • Introduction to BBP
      • Importance of Web Application Security
      • Web Application Security Standards and Best Practices
      • Bug Bounty Hunting vs Penetration Testing
      • Phases of a Web Application Penetration Test
      • Understanding Scope, Ethics, Code of Conduct, etc.
      • Common Scoping Mistakes
      • Web Application Technologies Fundamentals
      • Reconnaissance and Information Gathering
      • Fingerprinting Web Technologies
      • Directory Enumeration and Brute Forcing
      • Burp Suite for Bug Hunter
      • Domain Discovery Part 1
      • Domain Discovery Part 2
      • Domain Discovery Part 3
      • Subdomain Enumeration using Subfinder
      • Subfinder: Configuring API
      • Subdomain Enumeration using AMASS
      • Subdomain Bruteforcing: FFuF
      • Subdomain Bruteforcing: GoBuster
      • Subdomain Bruteforcing: AMASS
      • Subdomain Bruteforcing: PureDNS
      • VHOST Enumeration Secrets
      • Filtering Live Domains/Subdomains
      • Subdomain Enumeration with Permutation #1
      • Subdomain Enumeration with Permutation #2
      • Finding Origin IP Address Part 1
      • Finding Origin IP Address Part 2
      • Content Discovery with Dirsearch
      • Recursive Content Enumeration
      • Content Discovery with FFUF like a pro!
      • Discovering Content Like a Pro
      • Introduction to Passive Enumeration
      • Passive Enumeration Using GetAllUrls
      • Passive Enumeration Using WayBackURLs
      • Passive Enumeration Using Combining Tools
      • Active Scanning Using Katana
      • How to Choose Right Wordlist for Target
      • Authentication and Authorization Attacks
      • Brute-force Attacks
      • Attacking MFA
      • IDOR – Insecure Direct Object Reference Attacks
      • Broken Access Control Attack
      • Testing a Website with Autorize
      • File Inclusion Vulnerabilities
      • Local File Inclusion (LFI) Attack
      • Remote File Inclusion (RFI) Attacks
      • File Inclusion Challenge Walkthrough
      • SQL Injection
      • Basic SQL Injection Attacks
      • Blind SQL Injection Attack
      • Time Based SQL Injection Attack
      • Second Order SQL Injection Attack
      • Cross-Site Scripting (XSS) Attack
      • Basic XSS Attacks
      • Stored XSS Attack
      • Dom-Based XSS Attacks
      • Command Injection Attacks
      • Blind Command Injection Attacks
      • Server-Side Template Injection (SSTI) Attack
      • XML External Entity (XXE) Injection Attacks
      • Insecure File Upload Client-Side Controls Bypass
      • Insecure File Upload Bypasses
      • Automated Scanners For Findings Bugs
      • Other Common Vulnerabilities
      • Cross-Site Request Forgery (CSRF) Attacks
      • Cross-Site Request Forgery (CSRF) Token Bypass
      • Server-Side Request Forgery (SSRF) Attacks
      • Blind Server-Side Request Forgery (SSRF)
      • Introduction to Subdomain Takeovers
      • Open Redirects Attacks
      • CMS Bug Hunting (WordPress)
      • WordPress User Enumeration
      • WordPress Core Version Enumeration
      • Wpscan Enumeration overview
      • Exploiting WordPress in Different Ways
      • Evasion Techniques During Bug Hunting
      • WAF Identification and Fingerprinting
      • Bypassing Input Validation and Encoding Techniques and many mores
      • Writing Effective Bug Hunting Report
      • Vulnerability Reporting and Disclosure (VDP)
      • How to Pick Bug Bounty Programs
      • You are Ready For Bug Hunting.. Start now

      Web Application Penetration Testing (Advanced)
      This module provides a complete, professional approach to web application penetration testing, covering pre-engagement, server-side, client-side, and advanced testing techniques. Learners will identify and exploit modern web vulnerabilities, including authentication, authorization, session management, injection flaws, business logic issues, API and advanced attack vectors, using real-world labs and scenarios to prepare for enterprise-grade web pentesting engagements.

      • Pre-Engagement of Web App Pentesting
      • Non-Disclosure Agreements of Web Pentesting
      • Rules of engagement of Web Pentesting
      • Goals of Web App Pentesting
      • Scope of Web App Pentesting
      • Time estimation of Web App Pentesting
      • Information gathering
      • Conduct Search Engine Discovery and Reconnaissance for Information Leakage
      • Fingerprint Web Server
      • Review Webpage Comments and Metadata for Information Leakage
      • Fingerprint Web Application Framework
      • Configuration and Deploy Management Testing
      • Test Network Infrastructure Configuration
      • Testing for Content Security Policy
      • Test File Extensions Handling for Sensitive Information
      • Review Old Backup and Unreferenced Files for Sensitive Information
      • Enumerate Infrastructure and Application Admin Interfaces
      • Test HTTP Methods
      • Test HTTP Strict Transport Security
      • Test RIA Cross Domain Policy
      • Test File Permission
      • Identity Management Testing
      • Test Role Definitions
      • Test User Registration Process
      • Test Account Provisioning Process
      • Testing for Account Enumeration and Guessable User Account
      • Testing for Weak or unenforced username policy
      • Test Permissions of Guest/Training Accounts
      • Test Account Suspension/Resumption Process
      • Authentication Testing
      • Testing for default credentials
      • Testing for Weak lock out mechanism
      • Testing for bypassing authentication schema
      • Test remember password functionality
      • Testing for Browser cache weakness
      • Testing for Weak password policy
      • Testing for Weak security question/answer
      • Testing for weak password change or reset functionalities
      • Testing for Weaker authentication in alternative channel
      • Authorization Testing
      • Testing Directory traversal/file include
      • Testing for bypassing authorization schema
      • Testing for Privilege Escalation
      • Testing for Insecure Direct Object References
      • Data Validation Testing
      • Testing for Reflected Cross Site Scripting
      • Testing for Stored Cross Site Scripting
      • Testing for HTTP Verb Tampering
      • Testing for HTTP Parameter pollution
      • Testing for SQL Injection
      • Testing for NoSQL injection
      • Testing for LDAP Injection
      • Testing for ORM Injection
      • Testing for XML Injection
      • Testing for SSI Injection
      • Testing for XPath Injection
      • Testing for Code Injection
      • Testing for Local File Inclusion
      • Testing for Remote File Inclusion
      • Testing for Command Injection
      • Testing for HTTP Splitting/Smuggling
      • Business logic Testing
      • Test Business Logic Data Validation
      • Test Ability to Forge Requests
      • Test Upload of Malicious Files
      • Client Side Testing
      • Testing for DOM based Cross Site Scripting
      • Testing for JavaScript Execution
      • Testing for HTML Injection
      • Testing for Client Side URL Redirect
      • Testing for CSS Injection
      • Testing for Client Side Resource Manipulation
      • Testing for Clickjacking
      • SQL injection vulnerability in WHERE clause allowing retrieval of hidden data
      • SQL injection vulnerability allowing login bypass
      • SQL injection attack, querying the database type and version on Oracle
      • SQL injection attack, querying the database type and version on MySQL and Microsoft
      • SQL injection attack, listing the database contents on Oracle
      • SQL injection UNION attack, determining the number of columns returned by the query
      • Blind SQL injection with conditional responses
      • Blind SQL injection with conditional errors
      • Visible error-based SQL injection
      • Blind SQL injection with time delays
      • Blind SQL injection with out-of-band interaction
      • Blind SQL injection with out-of-band data exfiltration
      • SQL injection with filter bypass via XML encoding
      • Reflected XSS into HTML context with nothing encoded
      • Stored XSS into HTML context with nothing encoded
      • DOM XSS in document.write sink using source location.search
      • DOM XSS in innerHTML sink using source location.search
      • Reflected XSS into attribute with angle brackets HTML-encoded
      • Stored XSS into anchor href attribute with double quotes HTML-encoded
      • DOM XSS in document.write sink using source location.search inside a select element
      • Reflected DOM XSS
      • Stored DOM XSS
      • Reflected XSS into HTML context with most tags and attributes blocked
      • Reflected XSS in canonical link tag
      • Exploiting cross-site scripting to steal cookies
      • Exploiting cross-site scripting to capture passwords
      • Exploiting XSS to perform CSRF
      • Reflected XSS with AngularJS sandbox escape without strings
      • Reflected XSS with AngularJS sandbox escape and CSP
      • Reflected XSS with event handlers and href attributes blocked
      • Reflected XSS in a JavaScript URL with some characters blocked
      • Reflected XSS protected by CSP, with CSP bypass
      • Reflected XSS protected by very strict CSP, with dangling markup attack
      • CSRF vulnerability with no defenses
      • CSRF where token validation depends on request method
      • CSRF where token validation depends on token being present
      • CSRF where token is not tied to user session
      • CSRF where token is tied to non-session cookie
      • CSRF where token is duplicated in cookie
      • SameSite Lax bypass via method override
      • SameSite Strict bypass via client-side redirect
      • SameSite Strict bypass via sibling domain
      • SameSite Lax bypass via cookie refresh
      • CSRF where Referer validation depends on header being present
      • Basic clickjacking with CSRF token protection
      • Clickjacking with form input data prefilled from a URL parameter
      • Clickjacking with a frame buster script
      • Exploiting clickjacking vulnerability to trigger DOM-based XSS
      • DOM XSS using web messages
      • DOM XSS using web messages and a JavaScript URL
      • DOM-based open redirection
      • DOM-based cookie manipulation
      • Exploiting DOM clobbering to enable XSS
      • Clobbering DOM attributes to bypass HTML filters
      • CORS vulnerability with basic origin reflection
      • CORS vulnerability with trusted null origin
      • CORS vulnerability with trusted insecure protocols
      • Exploiting XXE using external entities to retrieve files
      • Exploiting XXE to perform SSRF attacks
      • Blind XXE with out-of-band interaction
      • Blind XXE with out-of-band interaction via XML parameter entities
      • Exploiting blind XXE to exfiltrate data using a malicious external DTD
      • Exploiting blind XXE to retrieve data via error messages
      • Exploiting XInclude to retrieve files
      • Exploiting XXE via image file upload
      • Exploiting XXE to retrieve data by repurposing a local DTD
      • Basic SSRF against the local server
      • Basic SSRF against another back-end system
      • Blind SSRF with out-of-band detection
      • SSRF with filter bypass via open redirection vulnerability
      • Blind SSRF with Shellshock exploitation
      • SSRF with whitelist-based input filter
      • HTTP request smuggling, confirming a CL.TE vulnerability via differential responses
      • Exploiting HTTP request smuggling to reveal front-end request rewriting
      • Exploiting HTTP request smuggling to deliver reflected XSS
      • Response queue poisoning via H2.TE request smuggling
      • H2.CL request smuggling
      • HTTP/2 request smuggling via CRLF injection
      • HTTP/2 request splitting via CRLF injection
      • CL.0 request smuggling
      • HTTP request smuggling, obfuscating the TE header
      • Exploiting HTTP request smuggling to perform web cache poisoning
      • Bypassing access controls via HTTP/2 request tunnelling
      • Web cache poisoning via HTTP/2 request tunnelling
      • Client-side desync
      • Server-side pause-based request smuggling
      • Basic server-side template injection
      • Basic server-side template injection (code context)
      • Server-side template injection using documentation
      • Server-side template injection in a sandboxed environment
      • Server-side template injection with a custom exploit
      • File path traversal, simple case
      • File path traversal, traversal sequences blocked with absolute path bypass
      • File path traversal, traversal sequences stripped non-recursively
      • File path traversal, traversal sequences stripped with superfluous URL-decode
      • File path traversal, validation of file extension with null byte bypass
      • Unprotected admin functionality
      • Unprotected admin functionality with unpredictable URL
      • User role controlled by request parameter
      • User role can be modified in user profile
      • User ID controlled by request parameter
      • User ID controlled by request parameter, with unpredictable user IDs
      • User ID controlled by request parameter with data leakage in redirect
      • User ID controlled by request parameter with password disclosure
      • Insecure direct object references
      • URL-based access control can be circumvented
      • Multi-step process with no access control on one step
      • Referer-based access control
      • Username enumeration via different responses
      • Password reset broken logic
      • Username enumeration via subtly different responses
      • Username enumeration via response timing
      • Broken brute-force protection, IP block
      • Username enumeration via account lock
      • 2FA broken logic
      • Brute-forcing a stay-logged-in cookie
      • Password reset poisoning via middleware
      • Password brute-force via password change
      • Broken brute-force protection, multiple credentials per request
      • 2FA bypass using a brute-force attack
      • Manipulating WebSocket messages to exploit vulnerabilities
      • Cross-site WebSocket hijacking
      • Manipulating the WebSocket handshake to exploit vulnerabilities
      • Web cache poisoning with an unkeyed header
      • Web cache poisoning with an unkeyed cookie
      • Web cache poisoning with multiple headers
      • Targeted web cache poisoning using an unknown header
      • Web cache poisoning via an unkeyed query string
      • Web cache poisoning via a fat GET request
      • Web cache poisoning to exploit a DOM vulnerability via a cache with strict cacheability criteria
      • Combining web cache poisoning vulnerabilities
      • Internal cache poisoning
      • Modifying serialized objects
      • Modifying serialized data types
      • Using application functionality to exploit insecure deserialization
      • Arbitrary object injection in PHP
      • Exploiting Java deserialization with Apache Commons
      • Exploiting PHP deserialization with a pre-built gadget chain
      • Exploiting Ruby deserialization using a documented gadget chain
      • Developing a custom gadget chain for Java deserialization
      • Developing a custom gadget chain for PHP deserialization
      • Using PHAR deserialization to deploy a custom gadget chain
      • Information disclosure in error messages
      • Information disclosure on debug page
      • Source code disclosure via backup files
      • Authentication bypass via information disclosure
      • Information disclosure in version control history
      • Excessive trust in client-side controls
      • High-level logic vulnerability
      • Inconsistent security controls
      • Flawed enforcement of business rules
      • Low-level logic flaw
      • Inconsistent handling of exceptional input
      • Weak isolation on dual-use endpoint
      • Insufficient workflow validation
      • Authentication bypass via flawed state machine
      • Infinite money logic flaw
      • Authentication bypass via encryption oracle
      • Bypassing access controls using email address parsing discrepancies
      • Basic password reset poisoning
      • Host header authentication bypass
      • Web cache poisoning via ambiguous requests
      • Routing-based SSRF
      • SSRF via flawed request parsing
      • Host validation bypass via connection state attack
      • Password reset poisoning via dangling markup
      • Authentication bypass via OAuth implicit flow
      • SSRF via OpenID dynamic client registration
      • Forced OAuth profile linking
      • OAuth account hijacking via redirect_uri
      • Stealing OAuth access tokens via an open redirect
      • Stealing OAuth access tokens via a proxy page
      • Remote code execution via web shell upload
      • Web shell upload via Content-Type restriction bypass
      • Web shell upload via path traversal
      • Web shell upload via extension blacklist bypass
      • Web shell upload via obfuscated file extension
      • Remote code execution via polyglot web shell upload
      • Web shell upload via race condition
      • JWT authentication bypass via unverified signature
      • JWT authentication bypass via flawed signature verification
      • JWT authentication bypass via weak signing key
      • JWT authentication bypass via jwk header injection
      • JWT authentication bypass via jku header injection
      • JWT authentication bypass via kid header path traversal
      • JWT authentication bypass via algorithm confusion
      • JWT authentication bypass via algorithm confusion with no exposed key
      • Discovering vulnerabilities quickly with targeted scanning
      • Scanning non-standard data structures
      • Client-side prototype pollution via browser APIs
      • DOM XSS via client-side prototype pollution
      • DOM XSS via an alternative prototype pollution vector
      • Client-side prototype pollution via flawed sanitization
      • Client-side prototype pollution in third-party libraries
      • Privilege escalation via server-side prototype pollution
      • Detecting server-side prototype pollution without polluted property reflection
      • Bypassing flawed input filters for server-side prototype pollution
      • Remote code execution via server-side prototype pollution
      • Exfiltrating sensitive data via server-side prototype pollution
      • Accessing private GraphQL posts
      • Accidental exposure of private GraphQL fields
      • Finding a hidden GraphQL endpoint
      • Bypassing GraphQL brute force protections
      • Performing CSRF exploits over GraphQL
      • Limit overrun race conditions
      • Bypassing rate limits via race conditions
      • Multi-endpoint race conditions
      • Single-endpoint race conditions
      • Exploiting time-sensitive vulnerabilities
      • Partial construction race conditions
      • Detecting NoSQL injection
      • Exploiting NoSQL operator injection to bypass authentication
      • Exploiting NoSQL injection to extract data
      • Exploiting NoSQL operator injection to extract unknown fields
      • Exploiting LLM APIs with excessive agency
      • Exploiting vulnerabilities in LLM APIs
      • Indirect prompt injection
      • Exploiting insecure output handling in LLMs
      • Exploiting path mapping for web cache deception
      • Exploiting path delimiters for web cache deception
      • Exploiting exact-match cache rules for web cache deception

      API Pentesting For Professional
      This module delivers a hands-on, end-to-end approach to API security testing. Learners will understand API fundamentals, set up realistic labs, and perform reconnaissance, enumeration, and endpoint analysis. The module covers authentication and authorization flaws (BOLA, BFLA, JWT attacks), injection vulnerabilities, rate-limiting issues, mass assignment, excessive data exposure, SSRF, and vulnerability chaining, concluding with a final capstone challenge to simulate real-world API pentesting

      • Introduction to API Pentesting
      • Your Hacking Lab: Setup cRAPI
      • Your Hacking Lab: Setup VAPI
      • Introduction to Postman Tool
      • Introduction To Burpsuite
      • API Reconnaissance Passive
      • API Reconnaissance Active
      • Endpoint Analysis: Reverse Engineering an API
      • Reverse Engineering an API: Using APIs and Excessive Data Exposure
      • Scanning APIs: Finding Security Misconfiguration with ZAP
      • Enumerating APIs: Introduction to Enumeration
      • Enumerating APIs: Fuzzing APIs
      • Enumerating APIs: Discovery via Source Code
      • API Authorization Attacks: Introduction to Authorization
      • API Authorization Attacks: Broken Object Level Authorization (BOLA)
      • API Authorization Attacks: Broken Function Level Authorization
      • Classic Authentication Attacks
      • API Authentication Attacks: Introduction to Authentication
      • API Authentication Attacks: API Token Attacks
      • API Authentication Attacks: JSON Web Tokens (JWT): Attacking JWTs
      • Testing for Improper Assets Management: Improper Asset Management
      • API Injection: Introduction to Injection Attacks
      • API Injection: SQL Injection Lab
      • API Injection: SQL Injection Login Bypass
      • API Injection: NoSQL Injection Lab
      • Mass Assignment: Introduction to Mass Assignment
      • Testing Mass Assignment Attacks
      • Excessive Data Exposure: Introduction to Excessive Data Exposure
      • SSRF (Server-Side Request Forgery): Introduction to SSRF
      • Testing SSRF (Server-Side Request Forgery)
      • Evasion and Combining Techniques: Evasive Maneuvers
      • Chaining Vulnerabilities Command injection
      • Conclusion of API Pentesting

      Linux Privilege Escalation
      This module focuses on Linux enumeration and privilege escalation techniques used in real-world penetration testing. Learners will perform manual and automated enumeration, identify sensitive credentials and weak permissions, and exploit cron jobs, SUID/SGID binaries, and SUDO misconfigurations. The module also covers kernel exploitation, Linux capabilities abuse, service-level attacks (MySQL UDF), NFS exploitation, Docker escalation, and concludes with an advanced practical assessment, building strong hands-on Linux post-exploitation skills.

      • Introduction to Linux privilege Escalation
      • Intro to Enumeration
      • Manual Enumerations
      • Automatic Enumeration Techniques
      • Intro to Sensitive Credentials
      • Labs: Sensitive Credentials
      • Weak File Permissions & Exploitations
      • Introduction to Cron Jobs
      • Cron Exploitation: File Permissions
      • Cron Exploitation: PATH Manipulations
      • Cron Exploitation: Wild Cards
      • Intro to SUID/SGID
      • SUID Exploitation: Common Ways
      • SUID Exploitation: Environment Veriables
      • SUID Exploitation: Shared Objects
      • Intro to SUDO
      • SUDO Exploitation: Escape Sequences
      • SUDO Exploitation: Id_Perload
      • SUDO Exploitation: Id_Library_Path
      • Intro to Kernel Exploitation
      • Lab: Kernel Exploitation
      • Intro to Linux Capabilities
      • Capabilities Getcap Exploitation
      • Service Exploitation: MySQL User Defined Functions
      • Service Exploitation: MySQL User Defined Functions Labs
      • Intro to NFS
      • NFS Exploitation
      • Privilege Escalation with Docker
      • Conclusion of Linux Privilege Escalation

      Windows Privilege Escalation
      This module delivers a comprehensive, hands-on approach to Windows privilege escalation. Learners will perform manual and automated enumeration, understand UAC and Windows privilege architecture, and exploit service misconfigurations such as DLL hijacking, unquoted service paths, and weak permissions. The module covers credential harvesting, registry-based attacks, token impersonation techniques (RoguePotato, PrintSpoofer, JuicyPotato), and advanced exploits including kernel vulnerabilities, UAC bypasses, and insecure system components. It concludes with an advanced practical assessment, equipping learners with real-world Windows post-exploitation skills

      • Windows Enumeration: Automatic Enumeration
      • Windows Manual Enumeration
      • Windows User Access Control (UAC)
      • Windows Privilege Architectures
      • Abuse DLL Hijacking
      • Abuse Unquoted Service Paths
      • Abuse Weak Service Executable
      • Abuse Service Permissions
      • Privilege Escalation using Modern Web Services
      • Sensitive Credentials Exploitation
      • Sensitive Credentials Labs
      • Introduction to Windows Registry
      • Labs: Registry Attacks Elevated
      • Labs: Weak Registry Permissions
      • Labs: Registry Attacks Autorun
      • Introduction to Windows Privilege Escalation
      • Introduction to Token Impersonation Selmpersonate
      • Token Impersonation Selmpersonate RoguePotato
      • Token Impersonation Selmpersonate PrintSpoofer
      • Token Impersonation Selmpersonate PrintSpoofer
      • SeTakeOwnership Exploit
      • SetBackup Exploit
      • Insecure GUI Apps
      • Scheduled Tasks Exploitation
      • Startup Apps Exploitation
      • Vulnerable Software
      • Windows Kernel Exploitation
      • Windows UAC Bypass
      • Introduction to Kernel Exploitation
      • Conclusion of Windows Privilege Escalation

      Documentation & Report Writing During Pentesting

      Tags

      • pentesting

      A course by

      M
      mdhimelatikh

      Course Includes:

      • Price:
        ৳ 40,000.00 Original price was: ৳ 40,000.00.৳ 15,000.00Current price is: ৳ 15,000.00.
      • Instructor:mdhimelatikh
      • Lessons:754
      • Level:Expert
      ৳ 15,000.00 ৳ 40,000.00
      Wishlist
      Hi, Welcome back!
      Continue with Google
      Forgot Password?
      Don't have an account?  Register Now

      Share On:

      Courses You May Like

      active directory pentest
      ৳ 25,000.00 Original price was: ৳ 25,000.00.৳ 6,999.00Current price is: ৳ 6,999.00.
      • 93 Lessons
      • 0 Students
      Network Pentesting
      Active Directory Pentesting & Red Teaming
      cropped-hacked-by-himel-logo.png

      Hacked by Himel is a cybersecurity learning platform sharing ethical hacking, write-ups, and courses to help you master offensive and defensive security in Bangladesh.

      Add: Jashore, Bangladesh
      Call: +8801951045900
      Email: services@hbhsec.com

      Online Platform

      • Home
      • Blog
      • About US
      • Contact Us
      • Privacy Policy

      Links

      • Home
      • Courses
      • Blog
      • Contact Us

      Contacts

      Enter your email address to register to our newsletter subscription

      Icon-facebook Icon-youtube Icon-linkedin2 Icon-instagram Icon-twitter
      Copyright 2026 | All Rights Reserved
      Hacked By HimelHacked By Himel
      Sign inSign up

      Sign in

      Don’t have an account? Sign up
      Lost your password?

      Sign up

      Already have an account? Sign in
      Continue with Google

      Have Questions? WhatsApp Us