Courses / On-demand courses
Web Application Security
Find, prove and fix the OWASP Top 10 in real web applications.
Web Application Security is a self-paced online course: 9.5 hours of recorded sessions across 7 modules, with 6 graded by Nova, Square 1's AI tutor. The founding price is A$45, down from A$90. Start any time and keep your own pace.
Price: A$45A$9050% off
Founding price for the first cohort, until 21 October.
Founding price, one payment. Founding students keep their founding price on any second programme.
Founding intake
Spot holders hear the start date first.
Module by module
Module 1 · 60 min
How the web is attacked
Module 2 · 90 min · graded
Injection and broken access control
Module 3 · 90 min · graded
Authentication and sessions
Module 4 · 90 min · graded
XSS, CSRF and the browser
Module 5 · 60 min · graded
APIs, SSRF and misconfiguration
Module 6 · 60 min · graded
Testing with Burp Suite and AI
Module 7 · 120 min · graded
Project: a full web application assessment
- recorded hours
- 9.5
- modules, in order
- 7
- deployed projects
- 3
- graded checkpoints
- 6
Who it is for, and what you receive.
Developers, testers and IT people who know how a website works and want to find, prove and fix the OWASP Top 10 in real applications. No security background needed.
Before you start
You know how a website works and can read some code; no security background needed.
Skills
- OWASP Top 10
- Burp Suite
- API security
- secure code review
- reporting
- 1
The recorded sessions
Taught by an instructor, taken in order at your own pace, yours for twelve months.
- 2
Graded work after every module
Exercises and projects marked by Nova against a rubric you can read, with what you did well and what to fix.
- 3
The projects
Deployed and graded, each one on your record with its repository.
- 4
Your hiring plan
The same six-part plan the bootcamps use, run with the career agent.
- 5
The record and the certificate
Every grade at square1ai.com/u/{handle}; a credential ID that resolves at square1ai.com/verify.
- 6
Nova as your tutor
Help that is about your actual work, because it has read all of it.
The content plan, module by module.
9.5 recorded hours from an instructor, taken in order at your own pace. Nova grades the work at the end of each module.
How the web is attacked
Module 1 · 60 min
Watch and take notes; nothing to submit in this module.
- Python
- Docker
- GitHub
Requests, responses and trust
The OWASP Top 10
Rules of engagement
Injection and broken access control
Module 2 · 90 min
Graded at the end: Two findings proven and fixed in a lab app.
- PostgreSQL
- Python
- Docker
SQL and command injection
IDOR and privilege escalation
Fixes that hold
Authentication and sessions
Module 3 · 90 min
Graded at the end: A login flow broken, then hardened.
- Python
- Docker
- GitHub
Password and MFA flaws
Session handling
OAuth pitfalls
XSS, CSRF and the browser
Module 4 · 90 min
Graded at the end: Three client-side findings with fixes.
- Python
- Docker
- GitHub
Stored, reflected and DOM XSS
CSRF
Content Security Policy
APIs, SSRF and misconfiguration
Module 5 · 60 min
Graded at the end: An API assessment with fixes.
- Python
- Docker
- GitHub
API authorisation
SSRF
Headers and misconfiguration
Testing with Burp Suite and AI
Module 6 · 60 min
Graded at the end: A test plan run with tools and an AI assistant.
- Python
- Docker
- GitHub
Proxying and replay
Automation with care
AI as a second pair of eyes
Project: a full web application assessment
Module 7 · 120 min
Graded at the end: The assessment report, with every finding reproduced.
- Python
- Docker
- GitHub
Scope
Testing
Reproduction
The report
The projects.
Each is deployed and graded by Nova against a rubric you can read before you start.
- 1
A lab app, broken and fixed
In a deliberately vulnerable lab application, prove at least five OWASP Top 10 findings, then fix each in the code and show the attack no longer works.
You hand in
- Findings with reproduction steps
- Code fixes
- Retest evidence
The rubric requires
Every finding reproduces before the fix and fails after it.
- 2
An API assessment
Assess the API of a lab application for authorisation flaws, SSRF and data exposure, and propose fixes a developer could merge.
You hand in
- API test plan
- Findings with severity
- Proposed fixes
The rubric requires
Each finding has a working reproduction and a severity you can justify.
- 3
A full assessment
Run a full assessment of an authorised target, such as a lab app, a CTF target or a bug bounty programme within its rules, and write a report with an executive summary and developer-ready fixes.
You hand in
- Scope and authorisation
- Assessment report
- Reproduction evidence
The rubric requires
A grader reproduces every finding from the report alone.
What you can do at the end.
Web applications you have tested and fixed, and three graded projects on your record that show it.
- 1
Explain how web applications are attacked and where the OWASP Top 10 comes from.
- 2
Prove and fix injection and broken access control.
- 3
Break and harden authentication and session handling.
- 4
Find and fix XSS, CSRF and other client-side flaws.
- 5
Assess APIs for SSRF, misconfiguration and data exposure.
- 6
Run a structured assessment with Burp Suite and an AI assistant and write a report developers act on.
Roles this prepares you for
- Application security analyst
- Penetration tester (junior)
- Security-minded developer
No placement rate is shown, because there are no graduates to count yet. The roles above are what the projects are built for.
Your record at the end.
Every exercise and project is graded by Nova against a rubric you can read, and every grade is kept on one page an employer can open and run. This is what the programme writes to it.
- Graded, line by line
- Nova reads every submission against the brief and the rubric and returns a score, what you did well and what to fix.
- Module by module
- Each module ends in graded work; the next opens when you are ready, on your own schedule.
- Nova remembers
- Help is about your actual work, because the tutor has every submission and every failed exercise of yours.
- One page an employer can run
- Every grade and project at /verify. An employer opens it and runs the code.
Record, Web Application Security
Example
- ProjectGraded
A lab app, broken and fixed
Every finding reproduces before the fix and fails after it.
- ProjectGraded
An API assessment
Each finding has a working reproduction and a severity you can justify.
- ProjectGraded
A full assessment
A grader reproduces every finding from the report alone.
- Every moduleGraded
6 graded checkpoints
Each module ends in work Nova grades line by line against a rubric you can read.
- AfterKept
Your hiring plan
Target roles, the gap map, the proof to send, weekly actions and an interview log.
The entries, not the grades: those are yours to earn. The page lives at /verify and an employer needs no account to open it.
5 entries, at your own pace. 25 spots are open.
Reserve my spotHow we help you find a job.
Proof, not a certificate: the projects you deployed are the thing you show, and the tools below are yours to use.
- 1
Your hiring plan
The same six-part plan the bootcamps use: target roles, the gap map, the proof to send, weekly actions, an interview log, the outcome. You run it with the career agent.
- 2
A record an employer can run
Your graded projects on /verify. An employer opens it and runs the code.
- 3
The career agent
Paste a real job posting at /career and it maps the role to your graded work and what to do next.
- 4
The roles directory
Every role we prepare people for, what it pays and what it asks, at /roles.
- 5
A path to the live cohort
If you want the instructor, the gates and the hiring sprint, the bootcamp on the same subject is one waitlist away.
Questions people ask.
About Web Application Security, answered from the plan on this page.
Related programmes
- Cybersecurity Bootcamp · 12-week live bootcamp
- AI Security and Red-Teaming Bootcamp · 12-week live bootcamp
- Cloud Security Engineer Bootcamp · 12-week live bootcamp
How long is Web Application Security?
9.5 hours of recorded sessions across 7 modules, taken at your own pace. 6 of the modules end in work Nova grades.
Is Web Application Security live or self-paced?
Self-paced. The sessions are recorded by an instructor who does this work, and Nova, Square 1's AI tutor, grades every checkpoint and project against a rubric you can read.
How much does Web Application Security cost?
A$45 for the founding intake, paid once; the standard price is A$90. It is the same price in every country. Founding students keep their founding price on any second programme.
Who is Web Application Security for?
Developers, testers and IT people who know how a website works and want to find, prove and fix the OWASP Top 10 in real applications. No security background needed. Before you start: You know how a website works and can read some code; no security background needed.
What will I build in Web Application Security?
3 deployed projects: A lab app, broken and fixed, An API assessment and A full assessment. Each is graded against a published rubric and kept on a record an employer can open at /verify.
What skills does Web Application Security teach?
OWASP Top 10, Burp Suite, API security, secure code review and reporting. It prepares you for roles such as Application security analyst, Penetration tester (junior) and Security-minded developer.
Does Web Application Security guarantee a job?
No. No placement rate is published because there are no graduates to count yet. What you leave with is graded, deployed work on one record an employer can open and run, and a hiring plan you keep with the career agent.
How do I join Web Application Security?
Reserve one of the twenty-five founding spots on this page with your email. Spot holders hear the opening date first, and nothing is charged before you confirm. The price on this page is in Australian dollars and is the same in every country.
25 spots. Hold one of them.
25 founding spots. Recorded by an instructor who does this work, graded by Nova. Spot holders hear the opening date first, and nothing is charged before you confirm.
- You can test a web application and write a report a developer acts on
- Three graded projects on your record
About a minute. No account, no card, and nothing is charged until you confirm.
