Skip to content

Courses / On-demand courses

On demandRecorded by an instructor, graded by Nova

Web Application Security

Find, prove and fix the OWASP Top 10 in real web applications.

Web Application Security is a self-paced online course: 9.5 hours of recorded sessions across 7 modules, with 6 graded by Nova, Square 1's AI tutor. The founding price is A$45, down from A$90. Start any time and keep your own pace.

Price: A$45A$9050% off

Founding price for the first cohort, until 21 October.

Founding price, one payment. Founding students keep their founding price on any second programme.

Founding intake

Spot holders hear the start date first.

Reserve your spot

Three fields hold it. A few short questions after that.

No account, no card. Holding a spot is free, and you confirm before anything is charged. We use these details to place you, never to sell.

Get the course booklet

Web Application Security. PDF, 11 pages, 243 KB. Tell us who you are and it downloads straight away.

You are a

No account, no card. We email you a copy and may contact you about this course. We never sell your details. Privacy

Module by module

  1. Module 1 · 60 min

    How the web is attacked

  2. Module 2 · 90 min · graded

    Injection and broken access control

  3. Module 3 · 90 min · graded

    Authentication and sessions

  4. Module 4 · 90 min · graded

    XSS, CSRF and the browser

  5. Module 5 · 60 min · graded

    APIs, SSRF and misconfiguration

  6. Module 6 · 60 min · graded

    Testing with Burp Suite and AI

  7. Module 7 · 120 min · graded

    Project: a full web application assessment

recorded hours
9.5
modules, in order
7
deployed projects
3
graded checkpoints
6

Who it is for, and what you receive.

Developers, testers and IT people who know how a website works and want to find, prove and fix the OWASP Top 10 in real applications. No security background needed.

Before you start

You know how a website works and can read some code; no security background needed.

Skills

  • OWASP Top 10
  • Burp Suite
  • API security
  • secure code review
  • reporting
  1. 1

    The recorded sessions

    Taught by an instructor, taken in order at your own pace, yours for twelve months.

  2. 2

    Graded work after every module

    Exercises and projects marked by Nova against a rubric you can read, with what you did well and what to fix.

  3. 3

    The projects

    Deployed and graded, each one on your record with its repository.

  4. 4

    Your hiring plan

    The same six-part plan the bootcamps use, run with the career agent.

  5. 5

    The record and the certificate

    Every grade at square1ai.com/u/{handle}; a credential ID that resolves at square1ai.com/verify.

  6. 6

    Nova as your tutor

    Help that is about your actual work, because it has read all of it.

The content plan, module by module.

9.5 recorded hours from an instructor, taken in order at your own pace. Nova grades the work at the end of each module.

  1. How the web is attacked

    Module 1 · 60 min

    Watch and take notes; nothing to submit in this module.

    • Python
    • Docker
    • GitHub

    Requests, responses and trust

    The OWASP Top 10

    Rules of engagement

  2. Injection and broken access control

    Module 2 · 90 min

    Graded at the end: Two findings proven and fixed in a lab app.

    • PostgreSQL
    • Python
    • Docker

    SQL and command injection

    IDOR and privilege escalation

    Fixes that hold

  3. Authentication and sessions

    Module 3 · 90 min

    Graded at the end: A login flow broken, then hardened.

    • Python
    • Docker
    • GitHub

    Password and MFA flaws

    Session handling

    OAuth pitfalls

  4. XSS, CSRF and the browser

    Module 4 · 90 min

    Graded at the end: Three client-side findings with fixes.

    • Python
    • Docker
    • GitHub

    Stored, reflected and DOM XSS

    CSRF

    Content Security Policy

  5. APIs, SSRF and misconfiguration

    Module 5 · 60 min

    Graded at the end: An API assessment with fixes.

    • Python
    • Docker
    • GitHub

    API authorisation

    SSRF

    Headers and misconfiguration

  6. Testing with Burp Suite and AI

    Module 6 · 60 min

    Graded at the end: A test plan run with tools and an AI assistant.

    • Python
    • Docker
    • GitHub

    Proxying and replay

    Automation with care

    AI as a second pair of eyes

  7. Project: a full web application assessment

    Module 7 · 120 min

    Graded at the end: The assessment report, with every finding reproduced.

    • Python
    • Docker
    • GitHub

    Scope

    Testing

    Reproduction

    The report

The projects.

Each is deployed and graded by Nova against a rubric you can read before you start.

  1. 1

    A lab app, broken and fixed

    In a deliberately vulnerable lab application, prove at least five OWASP Top 10 findings, then fix each in the code and show the attack no longer works.

    You hand in

    • Findings with reproduction steps
    • Code fixes
    • Retest evidence

    The rubric requires

    Every finding reproduces before the fix and fails after it.

  2. 2

    An API assessment

    Assess the API of a lab application for authorisation flaws, SSRF and data exposure, and propose fixes a developer could merge.

    You hand in

    • API test plan
    • Findings with severity
    • Proposed fixes

    The rubric requires

    Each finding has a working reproduction and a severity you can justify.

  3. 3

    A full assessment

    Run a full assessment of an authorised target, such as a lab app, a CTF target or a bug bounty programme within its rules, and write a report with an executive summary and developer-ready fixes.

    You hand in

    • Scope and authorisation
    • Assessment report
    • Reproduction evidence

    The rubric requires

    A grader reproduces every finding from the report alone.

What you can do at the end.

Web applications you have tested and fixed, and three graded projects on your record that show it.

  1. 1

    Explain how web applications are attacked and where the OWASP Top 10 comes from.

  2. 2

    Prove and fix injection and broken access control.

  3. 3

    Break and harden authentication and session handling.

  4. 4

    Find and fix XSS, CSRF and other client-side flaws.

  5. 5

    Assess APIs for SSRF, misconfiguration and data exposure.

  6. 6

    Run a structured assessment with Burp Suite and an AI assistant and write a report developers act on.

Roles this prepares you for

  • Application security analyst
  • Penetration tester (junior)
  • Security-minded developer

No placement rate is shown, because there are no graduates to count yet. The roles above are what the projects are built for.

Your record at the end.

Every exercise and project is graded by Nova against a rubric you can read, and every grade is kept on one page an employer can open and run. This is what the programme writes to it.

Graded, line by line
Nova reads every submission against the brief and the rubric and returns a score, what you did well and what to fix.
Module by module
Each module ends in graded work; the next opens when you are ready, on your own schedule.
Nova remembers
Help is about your actual work, because the tutor has every submission and every failed exercise of yours.
One page an employer can run
Every grade and project at /verify. An employer opens it and runs the code.

Record, Web Application Security

Example

  1. Project

    A lab app, broken and fixed

    Every finding reproduces before the fix and fails after it.

    Graded
  2. Project

    An API assessment

    Each finding has a working reproduction and a severity you can justify.

    Graded
  3. Project

    A full assessment

    A grader reproduces every finding from the report alone.

    Graded
  4. Every module

    6 graded checkpoints

    Each module ends in work Nova grades line by line against a rubric you can read.

    Graded
  1. After

    Your hiring plan

    Target roles, the gap map, the proof to send, weekly actions and an interview log.

    Kept

The entries, not the grades: those are yours to earn. The page lives at /verify and an employer needs no account to open it.

5 entries, at your own pace. 25 spots are open.

Reserve my spot

How we help you find a job.

Proof, not a certificate: the projects you deployed are the thing you show, and the tools below are yours to use.

  1. 1

    Your hiring plan

    The same six-part plan the bootcamps use: target roles, the gap map, the proof to send, weekly actions, an interview log, the outcome. You run it with the career agent.

  2. 2

    A record an employer can run

    Your graded projects on /verify. An employer opens it and runs the code.

  3. 3

    The career agent

    Paste a real job posting at /career and it maps the role to your graded work and what to do next.

  4. 4

    The roles directory

    Every role we prepare people for, what it pays and what it asks, at /roles.

  5. 5

    A path to the live cohort

    If you want the instructor, the gates and the hiring sprint, the bootcamp on the same subject is one waitlist away.

Get the course booklet

Web Application Security. PDF, 11 pages, 243 KB. Tell us who you are and it downloads straight away.

You are a

No account, no card. We email you a copy and may contact you about this course. We never sell your details. Privacy

Questions people ask.

About Web Application Security, answered from the plan on this page.

Related programmes

How long is Web Application Security?

9.5 hours of recorded sessions across 7 modules, taken at your own pace. 6 of the modules end in work Nova grades.

Is Web Application Security live or self-paced?

Self-paced. The sessions are recorded by an instructor who does this work, and Nova, Square 1's AI tutor, grades every checkpoint and project against a rubric you can read.

How much does Web Application Security cost?

A$45 for the founding intake, paid once; the standard price is A$90. It is the same price in every country. Founding students keep their founding price on any second programme.

Who is Web Application Security for?

Developers, testers and IT people who know how a website works and want to find, prove and fix the OWASP Top 10 in real applications. No security background needed. Before you start: You know how a website works and can read some code; no security background needed.

What will I build in Web Application Security?

3 deployed projects: A lab app, broken and fixed, An API assessment and A full assessment. Each is graded against a published rubric and kept on a record an employer can open at /verify.

What skills does Web Application Security teach?

OWASP Top 10, Burp Suite, API security, secure code review and reporting. It prepares you for roles such as Application security analyst, Penetration tester (junior) and Security-minded developer.

Does Web Application Security guarantee a job?

No. No placement rate is published because there are no graduates to count yet. What you leave with is graded, deployed work on one record an employer can open and run, and a hiring plan you keep with the career agent.

How do I join Web Application Security?

Reserve one of the twenty-five founding spots on this page with your email. Spot holders hear the opening date first, and nothing is charged before you confirm. The price on this page is in Australian dollars and is the same in every country.

25 spots. Hold one of them.

25 founding spots. Recorded by an instructor who does this work, graded by Nova. Spot holders hear the opening date first, and nothing is charged before you confirm.

  • You can test a web application and write a report a developer acts on
  • Three graded projects on your record
Reserve my spot

About a minute. No account, no card, and nothing is charged until you confirm.