Skip to content

Latest commit

Β 

History

2 Commits

Folders and files

NameName
Last commit message
Last commit date
Β 
Β 

Repository files navigation

International Cybersecurity and Digital Forensics Academy

Web Application Security Fellowship (Phase 1 - Track A)

This repository contains all labs, code samples, vulnerable applications, and resources for the 6-Month Web Application Security fellowship track. This program provides a comprehensive deep-dive into web application security, from Linux fundamentals to professional penetration testing and reporting.

πŸ“š Program Overview

  • Track: Web Application Security (Phase 1 - Track A)
  • Total Duration: 26 Weeks
  • Total Credit Units: 37 Units
  • Core Environment: Kali Linux & Lab VMs

πŸ—‚ Repository Structure

was-fellowship-phase1/
β”‚
β”œβ”€β”€ πŸ“„ README.md                          # This file
β”œβ”€β”€ πŸ“„ LICENSE
β”œβ”€β”€ πŸ“ CODE_OF_CONDUCT.md
β”œβ”€β”€ πŸ“ CONTRIBUTING.md
β”‚
β”œβ”€β”€ πŸ“ COURSE-1-BVWS101-LINUX-NETWORKING-BASH/
β”‚   β”œβ”€β”€ πŸ“ WEEK-1-LINUX-BASICS/
β”‚   β”‚   β”œβ”€β”€ πŸ“ labs/
β”‚   β”‚   β”‚   β”œβ”€β”€ πŸ“„ LAB_GUIDE.md
β”‚   β”‚   β”‚   β”œβ”€β”€ πŸ“ exercises/
β”‚   β”‚   β”‚   └── πŸ“ solutions/
β”‚   β”‚   β”œβ”€β”€ πŸ“ slides/
β”‚   β”‚   └── πŸ“ resources/
β”‚   β”œβ”€β”€ πŸ“ WEEK-2-USERS-PERMISSIONS/
β”‚   β”œβ”€β”€ πŸ“ WEEK-3-NETWORKING-FUNDAMENTALS/
β”‚   └── πŸ“ WEEK-4-BASH-SCRIPTING/
β”‚
β”œβ”€β”€ πŸ“ COURSE-2-BVWS102-WEB-ESSENTIALS/
β”‚   β”œβ”€β”€ πŸ“ WEEK-1-HTTP-HTTPS/
β”‚   β”œβ”€β”€ πŸ“ WEEK-2-HTML-CSS-JS/
β”‚   β”œβ”€β”€ πŸ“ WEEK-3-APP-COMPONENTS/
β”‚   β”œβ”€β”€ πŸ“ WEEK-4-VULN-OVERVIEW/
β”‚   └── πŸ“ WEEK-5-SSL-TLS/
β”‚
β”œβ”€β”€ πŸ“ COURSE-3-BVWS103-OWASP-TOP-10/             # !! Use in controlled VMs only !!
β”‚   β”œβ”€β”€ πŸ“ WEEK-1-INJECTION/
β”‚   β”‚   β”œβ”€β”€ πŸ“ labs/
β”‚   β”‚   β”‚   β”œβ”€β”€ πŸ“„ LAB_GUIDE.md
β”‚   β”‚   β”‚   β”œβ”€β”€ πŸ“ sql-injection/
β”‚   β”‚   β”‚   └── πŸ“ command-injection/
β”‚   β”‚   └── πŸ“ solutions/
β”‚   β”œβ”€β”€ πŸ“ WEEK-2-XSS-CSRF/
β”‚   β”œβ”€β”€ πŸ“ WEEK-3-BROKEN-AUTH/
β”‚   β”œβ”€β”€ πŸ“ WEEK-4-MISCONFIG-DATA-EXPOSURE/
β”‚   └── πŸ“ WEEK-5-CTF-CHALLENGES/
β”‚
β”œβ”€β”€ πŸ“ COURSE-4-BVWS104-SECURE-CODING/
β”‚   β”œβ”€β”€ πŸ“ WEEK-1-PRINCIPLES/
β”‚   β”‚   β”œβ”€β”€ πŸ“ vulnerable-code/
β”‚   β”‚   └── πŸ“ secure-code/
β”‚   β”œβ”€β”€ πŸ“ WEEK-2-INPUT-VALIDATION/
β”‚   β”œβ”€β”€ πŸ“ WEEK-3-CODE-AUDIT/
β”‚   └── πŸ“ WEEK-4-SDLC-CHECKLIST/
β”‚
β”œβ”€β”€ πŸ“ COURSE-5-BVWS105-PENTEST-METHODOLOGIES/
β”‚   β”œβ”€β”€ πŸ“ WEEK-1-PLANNING-SCOPING/
β”‚   β”‚   └── πŸ“ templates/
β”‚   β”œβ”€β”€ πŸ“ WEEK-2-RECON/
β”‚   β”œβ”€β”€ πŸ“ WEEK-3-EXPLOITATION-PRIVESC/
β”‚   └── πŸ“ WEEK-4-REPORTING/
β”‚       └── πŸ“ templates/
β”‚
β”œβ”€β”€ πŸ“ COURSE-6-BVWS106-AUTH-SESSION-MGMT/
β”‚   β”œβ”€β”€ πŸ“ WEEK-1-AUTHENTICATION/
β”‚   β”œβ”€β”€ πŸ“ WEEK-2-AUTHORIZATION/
β”‚   └── πŸ“ WEEK-3-SESSION-MGMT/
β”‚
β”œβ”€β”€ πŸ“ COURSE-7-BVWS107-COMPLIANCE-REPORTING/
β”‚   β”œβ”€β”€ πŸ“ WEEK-1-COMPLIANCE-FRAMEWORKS/
β”‚   └── πŸ“ WEEK-2-REPORTING-REMEDIATION/
β”‚
β”œβ”€β”€ πŸ“ CAPSTONE-BVWS108-FINAL-PROJECT/
β”‚   β”œβ”€β”€ πŸ“„ PROJECT_GUIDELINES.md
β”‚   β”œβ”€β”€ πŸ“ target-applications/
β”‚   β”œβ”€β”€ πŸ“ example-reports/
β”‚   └── πŸ“ student-submissions/               # Private
β”‚
└── πŸ“ TOOLS-SETUP/
    β”œβ”€β”€ πŸ“„ VM-SETUP-GUIDE.md
    β”œβ”€β”€ πŸ“„ BURP-SETUP.md
    β”œβ”€β”€ πŸ“„ ZAP-SETUP.md
    └── πŸ“ config-files/

Table of Contents & Lab Index

Course 1: BVWS101 - Foundations of Linux, Networking & Bash Scripting

Week Lab Code Activity Name Status
1 LAB-1.1.3 Lab - Linux CLI Practice: File Navigation & User Permissions Mandatory
2 LAB-1.2.4 Lab - Hands-on Linux Permission Setting and Management Mandatory
3 LAB-1.3.6 Lab - Network Diagrams and Subnetting Exercises Mandatory
4 LAB-1.4.5 Lab - Write Simple Automation Scripts Mandatory

Course 2: BVWS102 - Web Application Security Essentials

Week Lab Code Activity Name Status
1 LAB-2.1.4 Lab - Analyze HTTP Requests/Responses Mandatory
2 LAB-2.2.3 Lab - Build Simple Webpages Mandatory
3 LAB-2.3.5 Practice - Identify Potential Security Weaknesses Mandatory
4 LAB-2.4.2 Lab - Vulnerability Identification Exercises Mandatory
5 LAB-2.5.4 Lab - Configure SSL on Test Environments Mandatory

Course 3: BVWS103 - OWASP Top 10 Vulnerabilities & Exploitation Techniques

Week Lab Code Activity Name Status
1 LAB-3.1.5 Lab - Hands-on SQLi & Command Injection Exploitation Mandatory
2 LAB-3.2.6 Lab - Identifying and Exploiting XSS & CSRF Mandatory
3 LAB-3.3.4 Lab - Testing Authentication Mechanisms Mandatory
4 LAB-3.4.7 Lab - Vulnerability Scanning with Burp Suite/ZAP Mandatory
5 LAB-3.5.8 Lab - OWASP Top 10 CTF-Style Challenges Mandatory

Course 4: BVWS104 - Secure Coding Practices and Input Validation

Week Lab Code Activity Name Status
1 LAB-4.1.3 Lab - Code Review of Sample Vulnerable Code Mandatory
2 LAB-4.2.5 Lab - Implement Secure Validation in Test Code Mandatory
3 LAB-4.3.6 Lab - Group Code Audit Exercises Mandatory
4 LAB-4.4.4 Lab - Create a Secure Coding Checklist Mandatory

Course 5: BVWS105 - Web Application Penetration Testing Methodologies

Week Lab Code Activity Name Status
1 LAB-5.1.4 Lab - Write a Penetration Test Plan Mandatory
2 LAB-5.2.5 Lab - Conduct Footprinting and Scanning Mandatory
3 LAB-5.3.6 Lab - Hands-on Exploitation and Privilege Escalation Mandatory
4 LAB-5.4.3 Lab - Write a Penetration Testing Report Mandatory

Course 6: BVWS106 - Authentication, Authorization, and Session Management

Week Lab Code Activity Name Status
1 LAB-6.1.4 Lab - Testing Common Authentication Flaws Mandatory
2 LAB-6.2.5 Lab - Implement Access Control Rules Mandatory
3 LAB-6.3.3 Lab - Analyze Session Handling & Mitigation Mandatory

Course 7: BVWS107 - Compliance, Reporting, and Remediation

Week Lab Code Activity Name Status
1 LAB-7.1.4 Lab - Study PCI-DSS & GDPR Case Studies Mandatory
2 LAB-7.2.6 Lab - Produce a Final Pentest Report & Remediation Plan Mandatory

Capstone Project: BVWS108 - Web Application Penetration Testing

Component Link Status
Guidelines CAPSTONE-GUIDELINES Mandatory
Target Applications TARGET-APPS Mandatory
Report Template REPORT-TEMPLATE Mandatory

⚠️ Ethical Use Warning

This repository contains materials for educational purposes only.

  • All labs, especially in COURSE-3-BVWS103-OWASP-TOP-10, must be conducted in a controlled, isolated environment.
  • Never test on systems or applications you do not explicitly own or have written permission to test.
  • By using this repository, you agree to use these skills and tools ethically and legally.

πŸ›  Tools & Setup

Detailed setup guides for all required tools (Kali Linux, Burp Suite, OWASP ZAP, Docker, etc.) can be found in the TOOLS-SETUP directory.


πŸ‘₯ Contributing & Support

  1. Read the Guides: Please read CONTRIBUTING.md and CODE_OF_CONDUCT.md first.
  2. Reporting Issues: Found a bug in a lab? Open a detailed Issue.
  3. Discussions: For questions and help, use the GitHub Discussions tab.

For other inquiries, please contact us at resources@aivtic.org.ng.


πŸ“œ License

This repository's original educational content is licensed under the Creative Commons Attribution-NonCommercial 4.0 International (CC BY-NC 4.0) license. All third-party tools and vulnerable applications are subject to their own licenses.

About

No description, website, or topics provided.

Resources

Stars

0 stars

Watchers

0 watching

Forks

Releases

Packages

Contributors