Hands-on walkthroughs from real security labs — PortSwigger, DVWA and OWASP Juice Shop. Every writeup shows three things: the vulnerability, how it is exploited, and the fix a developer would actually apply. This is the same work our course is built on.
Filter by category, open any writeup to read the full walkthrough. New entries are added as the practice continues.
These writeups are the raw material behind our Web Application Security & Penetration Testing course — twelve modules, every attack paired with its fix, and a full report you can show an employer. The founding batch is enrolling now.
Every technique on this page was performed in a deliberately vulnerable training application built for exactly this purpose — PortSwigger's Web Security Academy, DVWA or OWASP Juice Shop. No live system is ever a target. Learning these techniques is legal; applying them without written authorisation is not.