← Back to list

Want to do be an Ethical Web Pentester?

Here is a step-by-step weekly guide to get some practice!

Harry Ouaida · 2025-09-30 11:16 · 0 claps · 2.4 min read
#ethical-hacking #web-penetration-testing #web-vulnerabilities #sql-injection #dirb
Open on Medium ↗
Wiki topics: 🔒 · Cybersecurity

Want to do be an Ethical Web Pentester?

Here is a step-by-step weekly guide to get some practice!

Week 1

Activities: The Technology stack of a web application and web server is identified

Activity 1: Install Oracle VM VirtualBox/VMware

[embed]

[embed]

Bonus Content: Networking in VMware

[embed]

[embed]

Activity 2: Installing Windows and Ubuntu or any Linux Variant of your choice on virtual machines

[embed]

[embed]

Activity 3: Installing AMP, depending on your machine

<No Video Yet>

Week 2

Activities: For the week 2 activities students must complete the following:

Activity 1: Install Google Chrome and Firefox Browsers in Windows 10 VM

<No Video Yet>

Activity 2: Installing Postman App in Windows 10 VM

<No Video Yet>

Activity 3: Installing Wireshark in Windows 10 VM

[embed]

Week 3

Activities: For the week 3 complete the following:

Activity 1: Making an account on ZeroBank in Windows 10 VM (Please use only http://zero.webappsecurity.com/index.htmlLinks to an external site.), otherwise it will not work.

–Username- username Password- password

<No Video Yet>

Activity 2: Installing Kali Linux VM

[embed]

Bonus Activity Alpha: Install Docker (To run the containers in the following vidoes)

[embed]

Bonus Activity Beta: Install lots of tools on VirtualBox:

Ethical Hacking Lab with Docker, WebGoat, Juice Shop, WebScarab & ZAP

[embed]

Activity 3: Installing the WebGoat Server

[embed]

Week 4

Activities: Web server scanner software and web content scanner software are demonstrated

For the week 4 complete the following:

Activity 1: Installing Metasploitable2

–Username- msfadmin Password- msfadmin

VMware

[embed]

VirtualBox

[embed]

Activity 2: Crawling the website (with BurpSuite)

Use BurpSuite Community Edition installed in Kali Linux and follow the Video Link Crawling the website (with BurpSuite) to complete your Activity and take relevant screenshots

[embed]

Activity 3: Using Nikto to scan a web server (Metasploitable2 VM installed in Activity 1)

[embed]

Activity 4: Using DIRB to scan a web server (Metasploitable2 VM installed in Activity 1)

[embed]

Week 5

Activities: Spiderling for web applications and websites are described and demonstrated

For the week 5 activities student must complete the following:

Activity 1: Demonstrating OWASP ZAP

[embed]

Activity 2: Demonstrating WebScarab

[embed]

Week 6

Activities: Install web application proxy testing tools

For the week 6 activities student must complete the following:

Activity 1: Demonstrating intercept HTTP requests and responses using Burp Suite with Metasploitable2

[embed]

Activity 2: Demonstrating Proxy interception rules

[embed]

Week 7

Activities: Existing frameworks that identify common software vulnerabilities are investigated

For the week 7 activities student must complete the following:

Activity 1: Demonstrating SQL injection using WebGoat Server

[embed]

Week 8

Activities: Methods to determine injection weaknesses (SQLite) for web applications are described and demonstrated

For the week 8 activities student must complete the following:

Activity 1: Demonstrate methods to determine injection weaknesses for web applications using (SQLMAP).

[embed]

Week 9

Activities: Methods for basic Broken Authentication.

For the week 9 activities student must complete the following:

Activity 1: Demonstrating methods for basic Broken Authentication.

[embed]

Week 10

Activities: Methods for basic Cross Site Scripting (XSS) weaknesses for web applications are described and demonstrated

For the week 10 activities student must complete the following:

Activity 1: Demonstrating methods for basic Cross Site Scripting weaknesses for web applications.

[embed]

[embed]

Week 11

Activities: Methods for Insecure Direct Object Reference (IDOR) weaknesses for web applications

For the week 11 activities student must complete the following:

Activity 1: Demonstrating methods for Insecure Direct Object Reference (IDOR) weaknesses.

[embed]

Week 12

Activities: Methods for Session Cookies weaknesses are described and demonstrated

For the week 12 activities student must complete the following:

Activity 1: Stolen Cookie

<No Video Yet>

Activity 2: Session Management Weakness with Cookies

<No Video Yet>


메타데이터
post_id
aeaafff2ceba
slug
want-to-do-be-an-ethical-web-pentester-aeaafff2ceba
url
https://medium.com/@networkhaz/want-to-do-be-an-ethical-web-pentester-aeaafff2ceba
canonical_url
https://medium.com/@networkhaz/want-to-do-be-an-ethical-web-pentester-aeaafff2ceba
author_url
https://medium.com/@networkhaz
status
ok
fetched_at
2026-06-20 20:29:01