Application Security & Bug Bounty Hunting
BSCP-grade web hacking + a real bounty deliverable
A 16-week course that turns a curious learner into a bounty-earning web app hunter and an AppSec engineer comfortable in modern stacks (SPAs, APIs, GraphQL, microservices). Finishes with the BSCP exam and a bug bounty deliverable. Covers OWASP Top 10 + API Top 10 + LLM Top 10. Sources merged: PortSwigger Web Security Academy, BSCP, OSWE, eWPT, OWASP.
Lessons
- How the Modern Web Actually Works
- Burp Suite Mastery
- Recon & Attack Surface Mapping
- Authentication & Session Attacks
- Access Control & IDOR
- Injection (SQL, NoSQL, Command, LDAP)
- XSS, CSRF, CORS
- SSRF, XXE, File Upload, Deserialization
- SSTI & Logic Flaws
- API Security
- HTTP Request Smuggling & Cache Attacks
- Modern Stacks: Frontend Frameworks, Microservices, Supply Chain
- Mobile App Testing (Intro)
- Source Code Review (White-Box AppSec)
- Bug Bounty Operations
- Capstone: BSCP Exam + Real-World Engagement