Want to do be an Ethical Web Pentester?
Here is a step-by-step weekly guide to get some practice!
Want to do be an Ethical Web Pentester?

Here is a step-by-step weekly guide to get some practice!
Week 1
Activities: The Technology stack of a web application and web server is identified
Activity 1: Install Oracle VM VirtualBox/VMware
[embed]
[embed]
Bonus Content: Networking in VMware
[embed]
[embed]
Activity 2: Installing Windows and Ubuntu or any Linux Variant of your choice on virtual machines
[embed]
[embed]
Activity 3: Installing AMP, depending on your machine
<No Video Yet>
Week 2
Activities: For the week 2 activities students must complete the following:
Activity 1: Install Google Chrome and Firefox Browsers in Windows 10 VM
<No Video Yet>
Activity 2: Installing Postman App in Windows 10 VM
<No Video Yet>
Activity 3: Installing Wireshark in Windows 10 VM
[embed]
Week 3
Activities: For the week 3 complete the following:
Activity 1: Making an account on ZeroBank in Windows 10 VM (Please use only http://zero.webappsecurity.com/index.htmlLinks to an external site.), otherwise it will not work.
–Username- username Password- password
<No Video Yet>
Activity 2: Installing Kali Linux VM
[embed]
Bonus Activity Alpha: Install Docker (To run the containers in the following vidoes)
[embed]
Bonus Activity Beta: Install lots of tools on VirtualBox:
Ethical Hacking Lab with Docker, WebGoat, Juice Shop, WebScarab & ZAP
[embed]
Activity 3: Installing the WebGoat Server
[embed]
Week 4
Activities: Web server scanner software and web content scanner software are demonstrated
For the week 4 complete the following:
Activity 1: Installing Metasploitable2
–Username- msfadmin Password- msfadmin
VMware
[embed]
VirtualBox
[embed]
Activity 2: Crawling the website (with BurpSuite)
Use BurpSuite Community Edition installed in Kali Linux and follow the Video Link Crawling the website (with BurpSuite) to complete your Activity and take relevant screenshots
[embed]
Activity 3: Using Nikto to scan a web server (Metasploitable2 VM installed in Activity 1)
[embed]
Activity 4: Using DIRB to scan a web server (Metasploitable2 VM installed in Activity 1)
[embed]
Week 5
Activities: Spiderling for web applications and websites are described and demonstrated
For the week 5 activities student must complete the following:
Activity 1: Demonstrating OWASP ZAP
[embed]
Activity 2: Demonstrating WebScarab
[embed]
Week 6
Activities: Install web application proxy testing tools
For the week 6 activities student must complete the following:
Activity 1: Demonstrating intercept HTTP requests and responses using Burp Suite with Metasploitable2
[embed]
Activity 2: Demonstrating Proxy interception rules
[embed]
Week 7
Activities: Existing frameworks that identify common software vulnerabilities are investigated
For the week 7 activities student must complete the following:
Activity 1: Demonstrating SQL injection using WebGoat Server
[embed]
Week 8
Activities: Methods to determine injection weaknesses (SQLite) for web applications are described and demonstrated
For the week 8 activities student must complete the following:
Activity 1: Demonstrate methods to determine injection weaknesses for web applications using (SQLMAP).
[embed]
Week 9
Activities: Methods for basic Broken Authentication.
For the week 9 activities student must complete the following:
Activity 1: Demonstrating methods for basic Broken Authentication.
[embed]
Week 10
Activities: Methods for basic Cross Site Scripting (XSS) weaknesses for web applications are described and demonstrated
For the week 10 activities student must complete the following:
Activity 1: Demonstrating methods for basic Cross Site Scripting weaknesses for web applications.
[embed]
[embed]
Week 11
Activities: Methods for Insecure Direct Object Reference (IDOR) weaknesses for web applications
For the week 11 activities student must complete the following:
Activity 1: Demonstrating methods for Insecure Direct Object Reference (IDOR) weaknesses.
[embed]
Week 12
Activities: Methods for Session Cookies weaknesses are described and demonstrated
For the week 12 activities student must complete the following:
Activity 1: Stolen Cookie
<No Video Yet>
Activity 2: Session Management Weakness with Cookies
<No Video Yet>
메타데이터
- post_id
- aeaafff2ceba
- slug
- want-to-do-be-an-ethical-web-pentester-aeaafff2ceba
- url
- https://medium.com/@networkhaz/want-to-do-be-an-ethical-web-pentester-aeaafff2ceba
- canonical_url
- https://medium.com/@networkhaz/want-to-do-be-an-ethical-web-pentester-aeaafff2ceba
- author_url
- https://medium.com/@networkhaz
- status
- ok
- fetched_at
- 2026-06-20 20:29:01