🌐🔥 Project 5: Web Application Security Lab — OWASP Top 10
Now we'll combine everything you've learned about:
HTTP/HTTPS
Cookies & Sessions
APIs
SQL Injection
XSS
CSRF
Authentication
Access Control
The goal is to practice web security in a deliberately vulnerable application, not on real websites.
🎯 Project Objective
By completing this project, you'll learn how to:
• Identify common web vulnerabilities
• Understand how attacks work
• Analyze HTTP requests
• Use browser developer tools
• Practice with Burp Suite
• Document security findings
• Understand how vulnerabilities are fixed
🧪 Step 1: Set Up a Safe Lab
Use a deliberately vulnerable application such as:
• OWASP Juice Shop
• DVWA (Damn Vulnerable Web Application)
• WebGoat
These applications are specifically designed for security training.
👉 Run them locally or inside an isolated lab.
🛠️ Step 2: Understand the Application
Before testing anything, explore the application normally.
Look at:
• Login
• Registration
• Search
• Product pages
• User profiles
• Forms
• APIs
Your first goal is simply:
Understand how the application works.
🌐 Step 3: Inspect HTTP Requests
Open your browser's Developer Tools.
Go to:
• Network → Requests
Perform normal actions such as:
• Login
• Search
• Add an item
• Update a profile
Observe:
• HTTP method
• URL
• Headers
• Cookies
• Request body
• Response status
🕵️ Step 4: Use Burp Suite
Burp Suite is widely used for authorized web application security testing.
In your lab, learn to:
• Intercept requests
• Inspect parameters
• Modify test requests
• Compare responses
The important skill isn't simply clicking buttons.
👉 Learn what each request is doing.
💉 Step 5: Study SQL Injection
Use the vulnerable application to understand how improper input handling can affect database queries.
Learn:
• Why SQL Injection occurs
• How unsafe input reaches a database
• What the vulnerability can expose
• How parameterized queries prevent it
Don't test SQL injection against real websites without explicit authorization.
🖥️ Step 6: Study XSS
Use the lab to understand:
• Stored XSS
• Reflected XSS
• DOM-based XSS
Learn how malicious input can reach a browser and execute unexpectedly.
Then study defenses such as:
• Output encoding
• Input validation
• Content Security Policy (CSP)
• Secure cookie settings
🔐 Step 7: Study Authentication & Access Control
Look for vulnerabilities involving:
• Weak authentication
• Poor session management
• Missing authorization checks
• Excessive privileges
Ask:
"Can a normal user access something that should belong to another user or role?"
This teaches an important security principle:
Authentication ≠ Authorization
🧩 Step 8: Study Security Misconfiguration
Look for deliberately vulnerable configurations such as:
• Exposed debug information
• Default credentials
• Unnecessary services
• Missing security headers
Then learn how developers should fix them.
📋 Step 9: Create a Vulnerability Report
For every finding, document:
• Vulnerability: SQL Injection
• Severity: High
• Affected Component: Login form
• Description: Explain the security weakness.
• Impact: Explain what an attacker could potentially achieve.
• Evidence: Relevant request/response information.
• Recommendation: Explain how developers can fix it.
• Status: Open / Fixed
📊 Step 10: Build Your OWASP Checklist
Create a checklist covering:
• Broken Access Control
• Cryptographic Failures
• Injection
• Insecure Design
• Security Misconfiguration
• Vulnerable Components
• Authentication Failures
• Software/Data Integrity issues
• Logging & Monitoring failures
• Server-Side Request Forgery (SSRF)
The exact OWASP Top 10 categories can evolve over time, so use the current OWASP documentation when doing formal assessments.