
educationMar 22, 202616:17pending
Course 27 - Hacking Web Applications, Penetration Testing, CTF | Episode 17: Common Network and Web Application Vulnerabilities
About this episode
In this lesson, you’ll learn about:
You can listen and download our episodes for free on more than 10 different platforms:
https://linktr.ee/cybercode_academy
- Common network “low-hanging fruit” vulnerabilities, including:
- Anonymous FTP access
- Guest SMB shares
- Default credentials across services like SSH, RDP, and databases such as MySQL, PostgreSQL, and Microsoft SQL Server
- The risks of credential reuse across multiple systems
- Clear-text traffic risks, understanding how tools like Wireshark can reveal sensitive credentials when encryption is not enforced.
- Injection-based web attacks, including:
- SQL Injection (SQLi), where unsanitized input manipulates backend database queries
- OS Command Injection, where user input is executed directly by the underlying operating system
- File Inclusion vulnerabilities, distinguishing between:
- Local File Inclusion (LFI)
- Remote File Inclusion (RFI)
- Common bypass techniques such as null byte injections and encoding tricks
- Cross-Site Scripting (XSS) categories:
- Reflected XSS
- Stored XSS
- DOM-based XSS
- Authentication and session management flaws, including:
- Username enumeration
- Password spraying attacks
- Improper reliance on cookies for authorization decisions
- Client-side validation weaknesses, demonstrating how browser-side controls can be bypassed using interception tools like Burp Suite to manipulate parameters, hidden fields, and perform parameter pollution.
- Additional misconfigurations and risks, such as:
- Open redirects
- Open mail relays
- Logic flaws in applications, including online gaming systems
You can listen and download our episodes for free on more than 10 different platforms:
https://linktr.ee/cybercode_academy
Get every episode summarized
Each time CyberCode Academy publishes, we email you a written briefing from the transcript — the topics, who appeared, and any specific claims, with the ad reads skipped.
Email me new episodesFree for 3 shows. No card needed.
Hosts & guests
No transcript yet
This episode has not been transcribed. Request it and it moves to the front of the queue.
More episodes
More from CyberCode Academy

Course 42 - Mobile Malware Analysis Fundamentals | Episode 12: Dynamic Analysis...
CyberCode Academy
Sep 8, 202628:08completed

Course 42 - Mobile Malware Analysis Fundamentals | Episode 11: Dynamic Analysis...
CyberCode Academy
Sep 7, 202624:15pending

Course 42 - Mobile Malware Analysis Fundamentals | Episode 10: The Essentials of...
CyberCode Academy
Sep 6, 202623:12pending

Course 42 - Mobile Malware Analysis Fundamentals | Episode 9: Mastering Basic St...
CyberCode Academy
Sep 5, 202621:16completed