International Cybersecurity and Digital Forensics Academy
Web Application Security Fellowship (Phase 1 - Track A)
This repository contains all labs, code samples, vulnerable applications, and resources for the 6-Month Web Application Security fellowship track. This program provides a comprehensive deep-dive into web application security, from Linux fundamentals to professional penetration testing and reporting.
Track: Web Application Security (Phase 1 - Track A)
Total Duration: 26 Weeks
Total Credit Units: 37 Units
Core Environment: Kali Linux & Lab VMs
π Repository Structure
was-fellowship-phase1/
β
βββ π README.md # This file
βββ π LICENSE
βββ π CODE_OF_CONDUCT.md
βββ π CONTRIBUTING.md
β
βββ π COURSE-1-BVWS101-LINUX-NETWORKING-BASH/
β βββ π WEEK-1-LINUX-BASICS/
β β βββ π labs/
β β β βββ π LAB_GUIDE.md
β β β βββ π exercises/
β β β βββ π solutions/
β β βββ π slides/
β β βββ π resources/
β βββ π WEEK-2-USERS-PERMISSIONS/
β βββ π WEEK-3-NETWORKING-FUNDAMENTALS/
β βββ π WEEK-4-BASH-SCRIPTING/
β
βββ π COURSE-2-BVWS102-WEB-ESSENTIALS/
β βββ π WEEK-1-HTTP-HTTPS/
β βββ π WEEK-2-HTML-CSS-JS/
β βββ π WEEK-3-APP-COMPONENTS/
β βββ π WEEK-4-VULN-OVERVIEW/
β βββ π WEEK-5-SSL-TLS/
β
βββ π COURSE-3-BVWS103-OWASP-TOP-10/ # !! Use in controlled VMs only !!
β βββ π WEEK-1-INJECTION/
β β βββ π labs/
β β β βββ π LAB_GUIDE.md
β β β βββ π sql-injection/
β β β βββ π command-injection/
β β βββ π solutions/
β βββ π WEEK-2-XSS-CSRF/
β βββ π WEEK-3-BROKEN-AUTH/
β βββ π WEEK-4-MISCONFIG-DATA-EXPOSURE/
β βββ π WEEK-5-CTF-CHALLENGES/
β
βββ π COURSE-4-BVWS104-SECURE-CODING/
β βββ π WEEK-1-PRINCIPLES/
β β βββ π vulnerable-code/
β β βββ π secure-code/
β βββ π WEEK-2-INPUT-VALIDATION/
β βββ π WEEK-3-CODE-AUDIT/
β βββ π WEEK-4-SDLC-CHECKLIST/
β
βββ π COURSE-5-BVWS105-PENTEST-METHODOLOGIES/
β βββ π WEEK-1-PLANNING-SCOPING/
β β βββ π templates/
β βββ π WEEK-2-RECON/
β βββ π WEEK-3-EXPLOITATION-PRIVESC/
β βββ π WEEK-4-REPORTING/
β βββ π templates/
β
βββ π COURSE-6-BVWS106-AUTH-SESSION-MGMT/
β βββ π WEEK-1-AUTHENTICATION/
β βββ π WEEK-2-AUTHORIZATION/
β βββ π WEEK-3-SESSION-MGMT/
β
βββ π COURSE-7-BVWS107-COMPLIANCE-REPORTING/
β βββ π WEEK-1-COMPLIANCE-FRAMEWORKS/
β βββ π WEEK-2-REPORTING-REMEDIATION/
β
βββ π CAPSTONE-BVWS108-FINAL-PROJECT/
β βββ π PROJECT_GUIDELINES.md
β βββ π target-applications/
β βββ π example-reports/
β βββ π student-submissions/ # Private
β
βββ π TOOLS-SETUP/
βββ π VM-SETUP-GUIDE.md
βββ π BURP-SETUP.md
βββ π ZAP-SETUP.md
βββ π config-files/
Table of Contents & Lab Index
Course 1: BVWS101 - Foundations of Linux, Networking & Bash Scripting
Week
Lab Code
Activity Name
Status
1
LAB-1.1.3
Lab - Linux CLI Practice: File Navigation & User Permissions
Mandatory
2
LAB-1.2.4
Lab - Hands-on Linux Permission Setting and Management
Mandatory
3
LAB-1.3.6
Lab - Network Diagrams and Subnetting Exercises
Mandatory
4
LAB-1.4.5
Lab - Write Simple Automation Scripts
Mandatory
Course 2: BVWS102 - Web Application Security Essentials
Week
Lab Code
Activity Name
Status
1
LAB-2.1.4
Lab - Analyze HTTP Requests/Responses
Mandatory
2
LAB-2.2.3
Lab - Build Simple Webpages
Mandatory
3
LAB-2.3.5
Practice - Identify Potential Security Weaknesses
Mandatory
4
LAB-2.4.2
Lab - Vulnerability Identification Exercises
Mandatory
5
LAB-2.5.4
Lab - Configure SSL on Test Environments
Mandatory
Course 3: BVWS103 - OWASP Top 10 Vulnerabilities & Exploitation Techniques
Week
Lab Code
Activity Name
Status
1
LAB-3.1.5
Lab - Hands-on SQLi & Command Injection Exploitation
Mandatory
2
LAB-3.2.6
Lab - Identifying and Exploiting XSS & CSRF
Mandatory
3
LAB-3.3.4
Lab - Testing Authentication Mechanisms
Mandatory
4
LAB-3.4.7
Lab - Vulnerability Scanning with Burp Suite/ZAP
Mandatory
5
LAB-3.5.8
Lab - OWASP Top 10 CTF-Style Challenges
Mandatory
Course 4: BVWS104 - Secure Coding Practices and Input Validation
Week
Lab Code
Activity Name
Status
1
LAB-4.1.3
Lab - Code Review of Sample Vulnerable Code
Mandatory
2
LAB-4.2.5
Lab - Implement Secure Validation in Test Code
Mandatory
3
LAB-4.3.6
Lab - Group Code Audit Exercises
Mandatory
4
LAB-4.4.4
Lab - Create a Secure Coding Checklist
Mandatory
Course 5: BVWS105 - Web Application Penetration Testing Methodologies
Week
Lab Code
Activity Name
Status
1
LAB-5.1.4
Lab - Write a Penetration Test Plan
Mandatory
2
LAB-5.2.5
Lab - Conduct Footprinting and Scanning
Mandatory
3
LAB-5.3.6
Lab - Hands-on Exploitation and Privilege Escalation
Mandatory
4
LAB-5.4.3
Lab - Write a Penetration Testing Report
Mandatory
Course 6: BVWS106 - Authentication, Authorization, and Session Management
Week
Lab Code
Activity Name
Status
1
LAB-6.1.4
Lab - Testing Common Authentication Flaws
Mandatory
2
LAB-6.2.5
Lab - Implement Access Control Rules
Mandatory
3
LAB-6.3.3
Lab - Analyze Session Handling & Mitigation
Mandatory
Course 7: BVWS107 - Compliance, Reporting, and Remediation
Week
Lab Code
Activity Name
Status
1
LAB-7.1.4
Lab - Study PCI-DSS & GDPR Case Studies
Mandatory
2
LAB-7.2.6
Lab - Produce a Final Pentest Report & Remediation Plan
Mandatory
Capstone Project: BVWS108 - Web Application Penetration Testing
β οΈ Ethical Use Warning
This repository contains materials for educational purposes only.
All labs, especially in COURSE-3-BVWS103-OWASP-TOP-10 , must be conducted in a controlled, isolated environment .
Never test on systems or applications you do not explicitly own or have written permission to test.
By using this repository, you agree to use these skills and tools ethically and legally.
Detailed setup guides for all required tools (Kali Linux, Burp Suite, OWASP ZAP, Docker, etc.) can be found in the TOOLS-SETUP directory.
π₯ Contributing & Support
Read the Guides: Please read CONTRIBUTING.md and CODE_OF_CONDUCT.md first.
Reporting Issues: Found a bug in a lab? Open a detailed Issue .
Discussions: For questions and help, use the GitHub Discussions tab.
For other inquiries, please contact us at resources@aivtic.org.ng.
This repository's original educational content is licensed under the Creative Commons Attribution-NonCommercial 4.0 International (CC BY-NC 4.0) license. All third-party tools and vulnerable applications are subject to their own licenses.