More dates

Payment plans

How does it work?

  • Reserve your order today and pay over time in regular, automatic payments.
  • You’ll receive your tickets and items once the final payment is complete.
  • No credit checks or third-party accounts - just simple, secure, automatic payments using your saved card.

WS2 - Web Hacking 101

Share
DEF CON Workshops
Add to calendar
 

Description

Instructed by:  cale “calebot” smith

Level of Difficulty: Beginner

Abstract:

Most security training starts with slides. This workshop starts with a target. Students spend the majority of the course attacking a purpose-built web application across progressive labs covering the vulnerability classes that define modern web security.

Each module follows a difficulty curve. Entry-level labs present classic, unfiltered vulnerabilities for students to exploit independently. Difficulty escalates as filters and defenses appear, requiring adaptation and creative problem-solving. Failed payloads, broken assumptions, and dead ends are not setbacks. They are the learning journey. The frustration of a blocked payload and the persistence to find the bypass is how offensive intuition is built.

A final exploit chaining challenge ties everything together, combining findings across vulnerability classes to demonstrate how moderate issues chain into critical impact, the way real attacks work.

Students attack, fail, adapt, and break through. Hands-on exploitation and the willingness to struggle is the foundation of any security career. It starts here.

All you need is a laptop and persistence.

Pre-Requisites:

Students should have a basic understanding of how websites work. If you have used a web browser, filled out a login form, and have a general sense that there is a server somewhere handling your requests, you have enough to start. Familiarity with browser developer tools is helpful but not required as we cover the basics needed during setup. No prior security experience, programming knowledge, or specialized tooling is expected.

Students who have heard of concepts like SQL injection or cross-site scripting but never exploited them are in the right place. Students who have never heard of them are also in the right place. The course is designed to teach these concepts through hands-on exploitation rather than assume them as prerequisites.

The only tools required are a modern web browser and optionally Burp Suite Community Edition, which is free. All labs run in a cloud hosted browser-based environment with no VMs, no minimum RAM requirements, and no complex setup.

Powered by

Tickets for good, not greed Humanitix dedicates 100% of profits from booking fees to charity

Register

This event has passed

Register

This event has passed
DEF CON Workshops