Web Hacking Black Belt Edition Training in Saudi Arabia

  • Learn via: Online Instructor-Led / Classroom Based / Onsite
  • Duration: 5 Days
  • Level: Expert
  • Price: From €6,000 +TAX
  • Upcoming Date:
  • UK & Türkiye Based Global Training Provider

Web Hacking Black Belt Edition is an advanced application security course focused on identifying and testing vulnerabilities in modern web applications, APIs, and related endpoints.

The course concentrates on specific areas of application security, advanced vulnerability discovery, and exploitation techniques. Participants will examine security issues that have affected real-world products, appeared in bug bounty programs, and are often missed by modern automated scanners.

The training includes a wide range of current and unconventional web security scenarios. Participants also benefit from access to a state-of-the-art Hacklab throughout the course, allowing the concepts to be reinforced through practical exercises.

Key topics include modern JWT, SAML, and OAuth weaknesses, core business logic issues, cryptographic flaws, RCE scenarios involving serialization and template injection, exploitation over DNS channels, advanced SSRF, HPP, XXE, and SQL Injection topics, serverless security issues, web caching vulnerabilities, and attack chaining based on real-world examples.

Participants are encouraged to become familiar with Burp Suite before attending in order to gain maximum value from the course.

We can organize this training at your preferred date and location. Contact Us!

Who Should Attend

This course is designed for:

  • Web developers
  • Intermediate-level penetration testers
  • DevOps engineers
  • Network engineers
  • Security researchers and analysts
  • Security architects
  • Security professionals and enthusiasts
  • Anyone looking to take their web security skills to a more advanced level

What You Will Learn

By the end of the course, participants should be able to:

  • Apply security testing techniques to identify and safely validate complex web vulnerabilities that may be missed by scanners and other automated tools.
  • Shape testing around real-world attacker behaviour and commonly used tooling so that assessments remain relevant to the threats facing an organisation.
  • Adapt offensive security tools to create more tailored testing approaches rather than relying only on standard payloads.
  • Recommend controls and corrective actions that reduce the conditions in which vulnerabilities may emerge.
  • Understand the potential business impact of web vulnerabilities and communicate that impact to relevant stakeholders.
  • Take greater responsibility within security teams and support stronger security awareness across the wider organisation.

Training Outline

Course Structure

The course content is built around carefully selected advanced topics from the current web hacking landscape.

Participants are provided with a customised Kali image containing a range of tools and plugins designed to support the analysis and testing of the vulnerabilities discussed during the course.

The training is delivered by an experienced penetration tester. Real-world stories and case studies help place the technical content into context, while access to a hacking lab, scripts, tools, and student handouts supports the practical learning process.

Detailed answer sheets are also provided at the end of the course, offering step-by-step walkthroughs for the exercises completed during the training.


Lab Setup and Architecture Overview

  • Introduction to the lab environment
  • Overview of the training architecture

Introduction to Burp Features

  • Key Burp Suite capabilities used throughout the course

Attacking Authentication and SSO

  • Token hijacking attacks
  • Logical bypass and boundary conditions
  • Bypassing two-factor authentication
  • Authentication bypass through subdomain takeover
  • JWT/JWS token attacks
  • SAML authorization bypass
  • OAuth issues

Password Reset Attacks

  • Session poisoning
  • Host Header validation bypass
  • Case studies involving common password reset failures

Business Logic and Authorization Flaws

  • Mass Assignment
  • Invite and Promo Code bypass
  • Replay Attack
  • API Authorization bypass
  • HTTP Parameter Pollution (HPP)

XML External Entity (XXE)

  • XXE fundamentals
  • Advanced XXE exploitation through OOB channels
  • XXE through SAML
  • XXE in file parsing

Breaking Crypto

  • Known Plaintext Attack
  • Faulty password reset scenarios
  • Padding Oracle Attack
  • Hash length extension attacks
  • Authentication bypass using .NET Machine Key
  • Padding oracle scenarios involving fixed IVs

Remote Code Execution (RCE)

  • Java Serialization
  • .NET Serialization
  • PHP Serialization
  • Python Serialization
  • Server-Side Template Injection
  • Code injection over OOB channels

SQL Injection Masterclass

  • Second-order injection
  • Out-of-Band exploitation
  • SQL Injection through cryptographic workflows
  • OS code execution through PowerShell
  • Advanced SQL Injection topics
  • Advanced SQLMap usage and WAF bypass
  • Penetration testing GraphQL

Tricky File Upload

  • Malicious file extensions
  • Circumventing file validation checks
  • Testing hardened web servers
  • SQL Injection through file metadata

Server-Side Request Forgery (SSRF)

  • SSRF against internal network resources
  • SSRF involving templates and extensions
  • SSRF filter bypass techniques
  • Case studies

Attacking the Cloud

  • SSRF exploitation
  • Serverless exploitation
  • Google Dorking in the cloud era
  • Cognito misconfiguration and data exfiltration
  • Post-exploitation techniques for cloud-hosted applications
  • Case studies

Attacking Hardened CMS Platforms

  • Identifying and assessing different CMS platforms
  • Hardened WordPress, Joomla, and SharePoint environments

Web Caching Attacks

  • Security weaknesses associated with web caching

Miscellaneous Vulnerabilities

  • Unicode normalization attacks
  • Second-order IDOR
  • Misconfigured code control systems
  • HTTP Desync attacks

Attack Chaining

  • Multi-stage vulnerability chaining
  • N-tier vulnerability chaining
  • Attack sequences that may lead to RCE

Case Studies

  • Real-world web security examples
  • Unusual XSS and CSRF scenarios

B33r-101

  • Dedicated course section


Exams and Assessments

This course includes a formal examination as part of the programme.

The exam is provided by NotSoSecure and is included in the course fee. Details such as the assessment format, duration, number of questions, and passing score will be confirmed by the QA account manager or instructor before the exam.

Why Choose Us

Experience Web Hacking Black Belt Edition in Saudi Arabia through Bilginç IT Academy's live and interactive virtual classroom environment, accessible from your home, office, or any location. Connect with expert trainers in real time and bring the energy of classroom learning into the digital experience.

  • Live Instructor-Led Sessions: Join scheduled training sessions with your instructor and fellow delegates in real time.
  • Interactive Learning Experience: Take part in discussions, practical exercises, group activities, and Q&A sessions throughout the course.
  • Expert Trainer Network: Learn from experienced trainers with strong industry backgrounds and practical field expertise.
  • Over 30 Years of Training Expertise: Benefit from Bilginç IT Academy's long-standing experience in delivering professional training since 1995.
  • Flexible and Scalable Delivery: Access live virtual classrooms from Saudi Arabia and worldwide, with flexible planning options for individual and corporate training needs.

Experience Web Hacking Black Belt Edition in a focused classroom environment in Saudi Arabia. Bilginç IT Academy's carefully selected training venues provide a professional setting where delegates can interact directly with expert trainers and peers.

  • Experienced Trainers: Learn from specialists with extensive field experience and real-world knowledge.
  • Professional Training Venues: Attend courses in comfortable, well-equipped classrooms designed to support effective learning.
  • Focused Classroom Experience: Benefit from limited class sizes that encourage discussion, interaction, and personalized support.
  • Quality-Driven Learning: Develop practical skills through structured, up-to-date, and professionally designed training content.

Meet your team's training needs with Bilginç IT Academy's onsite Web Hacking Black Belt Edition in Saudi Arabia solution, delivered at your office or preferred location. Align your team's development with your business goals through a training experience tailored to your organization.

  • Tailored Course Content: Adapt the training program to your organization's projects, team structure, and specific business requirements.
  • Time and Cost Efficiency: Reduce travel, accommodation, and operational costs while maximizing the value of your training investment.
  • Team-Focused Learning: Help your employees develop around the same knowledge base and strengthen collaboration across your organization.
  • Simplified Planning and Tracking: Manage the training process, participant development, and organizational requirements with greater control.


Contact us for more detail about our trainings and for all other enquiries!

Web Hacking Black Belt Edition Training Course in Saudi Arabia Schedule

Join our public courses in our Saudi Arabia facilities. Private class trainings will be organized at the location of your preference, according to your schedule.

We can organize this training at your preferred date and location.
13 Rabiʻ I 1448 (5 Days)
Riyadh, Jeddah, Dammam, Neom
€6,000 +TAX
21 Rabiʻ I 1448 (5 Days)
Riyadh, Jeddah, Dammam, Neom
€6,000 +TAX
25 Rabiʻ I 1448 (5 Days)
Riyadh, Jeddah, Dammam, Neom
€6,000 +TAX
29 Rabiʻ I 1448 (5 Days)
Riyadh, Jeddah, Dammam, Neom
€6,000 +TAX
10 Rabiʻ II 1448 (5 Days)
Riyadh, Jeddah, Dammam, Neom
€6,000 +TAX
11 Rabiʻ II 1448 (5 Days)
Riyadh, Jeddah, Dammam, Neom
€6,000 +TAX
20 Rabiʻ II 1448 (5 Days)
Riyadh, Jeddah, Dammam, Neom
€6,000 +TAX
30 Rabiʻ II 1448 (5 Days)
Riyadh, Jeddah, Dammam, Neom
€6,000 +TAX

Other trainings and courses related to the Web Hacking Black Belt Edition

Saudi Arabia is currently undergoing one of the most significant digital transformations in modern history under the umbrella of Vision 2030. Riyadh, Jeddah, and the revolutionary smart-city project NEOM are at the forefront of this technological leap, focusing on non-oil economic growth through digital innovation. The Kingdom is investing billions into cloud infrastructure, AI research, and cybersecurity to protect its national interests and support a burgeoning private tech sector. Our educational frameworks in Saudi Arabia are aligned with this national transformation, providing the workforce with essential skills to manage mega-scale digital projects. We empower Saudi professionals to take the lead in building a tech-driven future that honors the Kingdom's heritage while embracing the possibilities of the Fourth Industrial Revolution.

By using this website you agree to let us use cookies. For further information about our use of cookies, check out our Cookie Policy.