Performance & Security · Intermediate · 💎 Premium
Web Security Testing for QA — OWASP Top 10 Hands-on
Test web apps and APIs for the OWASP Top 10 using Juice Shop, Burp/ZAP and CVSS — safely, legally, and the way employers expect.
10Lessons
71Lab tasks
13h 15mDuration
1Capstone + certificate
About this course
A practical, defensive security-testing course for QA engineers and testers. You learn to verify security requirements and report findings against the OWASP Top 10 and API Top 10 — using an intercepting proxy, DevTools, and automated scanners — with every lab run only against your own local OWASP Juice Shop. The course ends with a portfolio-ready security test plan and findings report scored with CVSS.
What you will be able to do
- Test web applications and APIs against the OWASP Top 10 and OWASP API Top 10 using a local, legal lab
- Set up and use an intercepting proxy (Burp Suite Community or OWASP ZAP) to inspect and modify requests
- Detect broken access control and IDOR/BOLA by testing authorisation at the API level
- Safely detect SQL injection and XSS and turn findings into clear test cases
- Verify authentication, session management and JWT handling with negative and edge-case tests
- Run automated ZAP baseline and dependency scans and wire them into CI
- Write professional, reproducible security bug reports and score severity with CVSS 3.1
- Produce a portfolio-ready security test plan and findings report for a local target
Syllabus
-
▶
1. Security Testing for QA: CIA, STRIDE, OWASP Top 10, Ethics & Juice Shop Setup Build the mental model a QA engineer needs for security work — the CIA triad, STRIDE threat modeling, the OWASP Top 10 2021, the legal/ethical rules you must follow, and a running Juice Shop lab.
-
🔒
2. HTTP, Cookies, Sessions and Browser DevTools for Security Checks Learn exactly how requests, responses, cookies and sessions work, then use browser DevTools to inspect, read and reason about them like a security-aware tester.
-
🔒
3. Intercepting Proxies: Burp Suite Community & OWASP ZAP Setup Set up an intercepting proxy (Burp Suite Community or OWASP ZAP), route your browser through it, and intercept and modify requests to your local Juice Shop.
-
🔒
4. Broken Access Control & IDOR Test Cases Test the #1 OWASP risk: broken access control. Learn to write and run IDOR, forced-browsing and privilege-escalation test cases against your local Juice Shop.
-
🔒
5. Injection: Detecting SQLi & XSS and Writing Test Cases Learn how SQL injection and cross-site scripting arise, how to safely detect them on your local Juice Shop, and how to turn detections into clear test cases and bug reports.
-
🔒
6. Authentication & Session Management: Password Policy, MFA and JWT Checks Test authentication and session management: password policy, account lockout, session lifecycle, MFA behaviour, and common JWT weaknesses — all on your local Juice Shop.
-
🔒
7. Security Misconfiguration: Headers, TLS Checks & Sensitive Data Exposure Check security headers, TLS configuration and sensitive data exposure — the easy-to-miss misconfigurations that QA can catch quickly with simple tools.
-
🔒
8. Automated Scanning: ZAP Baseline in Docker/CI & Dependency Scanning Run an OWASP ZAP baseline scan in Docker against local Juice Shop, wire it into CI, and scan dependencies with npm audit and OWASP Dependency-Check.
-
🔒
9. API Security Testing (OWASP API Top 10) & Writing Reports with CVSS Apply security testing to APIs using the OWASP API Security Top 10, then write professional security bug reports and score severity with CVSS.
-
🔒
10. Capstone: Security Test Plan & Findings Report for Local Juice Shop Produce a complete, portfolio-ready security test plan and findings report for your local OWASP Juice Shop, following a professional structure and evaluation rubric.