Ethical Hacking for QA Engineers
Learn ethical hacking techniques for security testing. Master OWASP Top 10, Burp Suite, and security testing methodologies to find vulnerabilities before attackers do.
Membership required
Join Membership to unlock human reviews of your work, 21 advanced specializations, and higher coach limits. 1:1 mentorship comes with Pro later.
QA is not about proving it works; it is about proving it breaks. Learn to think like a hacker—exploring the "Dark Path," fuzzing inputs with the "Big List of Naughty Strings," and manipulating APIs to find cracks developers ignored.
1. The Dark Path
2. Business Logic Flaws
3. Simply Changing IDs
4. Conclusion
The Open Web Application Security Project (OWASP) maintains the "Hit List" of web vulnerabilities. Learn the top three risks—Broken Access Control (A01), Cryptographic Failures (A02), and Injection (A03)—and how to find them before hackers do.
1. A01: Access Control
2. A02: Crypto Failures
3. A03: Injection
4. Conclusion
To break the software, you must control the traffic. Learn to configure Burp Proxy, break HTTPS with a CA Certificate, and use the "Intercept" and "Repeater" tools to manipulate requests on the fly—changing prices, role IDs, and more.
1. Proxy Configuration
2. Intercept & Modify
3. Using Repeater
4. Conclusion
Injection is the art of confusing the machine. Learn how to break the parser using SQL Injection (Union & Blind), execute arbitrary code with Command Injection (RCE), and traverse XML trees with XPath Injection.
1. SQL Injection
2. Command Injection (RCE)
3. XPath Injection
4. Conclusion
Authentication is the front door. Learn how to verify that the door forces locks. Master Session Hijacking, JWT manipulation (None Algo, Signature stripping), and verify that "Logout" actually kills the session on the server.
1. Session Hijacking
2. JWT Attacks
3. Broken Logout
4. Conclusion
You are permitted to enter... but are you permitted to touch? Master the detection of IDOR (Insecure Direct Object References), Mass Assignment of Admin privileges, and finding "Hidden" endpoints that lack access control.
1. IDOR
2. Mass Assignment
3. Hidden Endpoints
4. Conclusion
Hijacking the browser. Learn how to execute Reflected, Stored, and DOM XSS to steal cookies, and understand how CSRF forces users to transfer money without their consent. Master the Content Security Policy (CSP) defense.
1. XSS: Script Injection
2. CSRF: Forced Actions
3. CSP Logic
4. Conclusion
Uploading a file seems harmless—until the server executes it. Learn how "Unrestricted File Uploads" lead to Webshells (RCE), and how "Insecure Deserialization" (Java/Python/PHP) turns data objects into remote command execution.
1. File Upload Attacks
2. Insecure Deserialization
3. Secure Handling
4. Conclusion
Finding the bug is half the battle. Reporting it effectively is the other half. Learn the Common Vulnerability Scoring System (CVSS 3.1) to calculate risk scores (e.g. 9.8 Critical) and master the art of writing professional security advisories that get fixed.
1. CVSS Scoring
2. Writing Advisories
3. Ethics
4. Conclusion
Putting it all together. A step-by-step methodology for conducting a security assessment on a new feature. Reconnaissance, Enumeration, Exploitation, and Reporting. Shift from "Tester" to "Red Teamer".
