WS2 - Web Hacking 101
Description
Instructed by: cale “calebot” smith
Level of Difficulty: Beginner
Abstract:
Most security training starts with slides. This workshop starts with a target. Students spend the majority of the course attacking a purpose-built web application across progressive labs covering the vulnerability classes that define modern web security.
Each module follows a difficulty curve. Entry-level labs present classic, unfiltered vulnerabilities for students to exploit independently. Difficulty escalates as filters and defenses appear, requiring adaptation and creative problem-solving. Failed payloads, broken assumptions, and dead ends are not setbacks. They are the learning journey. The frustration of a blocked payload and the persistence to find the bypass is how offensive intuition is built.
A final exploit chaining challenge ties everything together, combining findings across vulnerability classes to demonstrate how moderate issues chain into critical impact, the way real attacks work.
Students attack, fail, adapt, and break through. Hands-on exploitation and the willingness to struggle is the foundation of any security career. It starts here.
All you need is a laptop and persistence.
Pre-Requisites:
Students should have a basic understanding of how websites work. If you have used a web browser, filled out a login form, and have a general sense that there is a server somewhere handling your requests, you have enough to start. Familiarity with browser developer tools is helpful but not required as we cover the basics needed during setup. No prior security experience, programming knowledge, or specialized tooling is expected.
Students who have heard of concepts like SQL injection or cross-site scripting but never exploited them are in the right place. Students who have never heard of them are also in the right place. The course is designed to teach these concepts through hands-on exploitation rather than assume them as prerequisites.
The only tools required are a modern web browser and optionally Burp Suite Community Edition, which is free. All labs run in a cloud hosted browser-based environment with no VMs, no minimum RAM requirements, and no complex setup.
Tickets for good, not greed Humanitix dedicates 100% of profits from booking fees to charity


