Hogeschool West-Vlaanderen
Howest Brugge
Spoorwegstraat 4 - 8200 Brugge
Tel: 050 682666
studentadmin@howest.be - Website: www.howest.be
Web Pentesting Fundamentals17736/2013/2627/1/30
Study guide

Web Pentesting Fundamentals

17736/2013/2627/1/30
Academic year 2026-27
Is found in:
  • Bachelor of Cybersecurity, programme stage 2
This is a single course unit.
Study load: 3 credits
Total study time: 75,00 hours
Re-sit exam: is possible.
It is not possible to enrol in this course unit under
  • exam contract (to obtain a credit).
  • exam contract (to obtain a degree).
Co-ordinator: Audenaert Ann
Other teaching staff: Koreman Koen, Rizvi Syed Shan
Language course: No
Languages: English

Omschrijving Volgtijdelijkheid (VT) (EN)

to be taken together with Web frontend AND to be taken together with Programming Fundamentals AND to be taken together with Databases Fundamentals.

Omschrijving Doelstellingen (EN)

LR2:

02.1.1 Enumerates relevant sources of threat intelligence and recognizes their application domain

LR3:

03.1.1 Recognizes and describes current vulnerabilities, types of attacks, and attack vectors

03.1.2 Identifies OSINT resources and techniques for reconnaissance

03.1.4 Identifies and describes networks and protocols

03.1.5 Generalizes and clarifies the cybersecurity of databases

LR5:

05.2.3 Assesses security in a web development

LR9:

09.1.1 Describes the legislative, deontological and ethical framework around cybersecurity, data protection.

LR11:

11.1.1 Identifies and interprets the sources and organizations for cybersecurity knowledge

Omschrijving Inhoud (EN)

Web Pentesting Fundamentals consists of attacking Web environments. This is based on the OWASP top 10.

Several topics covered:

- Fingerprinting
- Broken authentication
- XSS
- SQLi
- ...

Omschrijving Studiematerialen (lijst) (EN)

CasesMandatory
PresentationMandatory
TutorialsMandatory

Omschrijving Eindcompetenties (lijst) (EN)

PBACS002: Collects, analyses, structures and shares actionable threat intelligence information that includes the behaviour, motives and capability of cybercriminals, including phishing and ransomware.
CodeDescription
PBACS002Collects, analyses, structures and shares actionable threat intelligence information that includes the behaviour, motives and capability of cybercriminals, including phishing and ransomware.
PBACS003: Across the full range of software, firmware and hardware technologies, evaluates and improves the cybersecurity of (sub)systems by detecting, analysing and dealing with existing attack vectors and vulnerabilities, this by deploying existing defensive and offensive security software, including developing proprietary scripts, penetration testing, digital footprint reduction and participating in red teaming exercises.
CodeDescription
PBACS003Across the full range of software, firmware and hardware technologies, evaluates and improves the cybersecurity of (sub)systems by detecting, analysing and dealing with existing attack vectors and vulnerabilities, this by deploying existing defensive and offensive security software, including developing proprietary scripts, penetration testing, digital footprint reduction and participating in red teaming exercises.
PBACS005: Contributes to structuring and optimising a secure development life cycle in which each phase is adequately protected by an appropriate combination of technical and organizational controls, tailored to specific requirements within relevant domains
CodeDescription
PBACS005Contributes to structuring and optimising a secure development life cycle in which each phase is adequately protected by an appropriate combination of technical and organizational controls, tailored to specific requirements within relevant domains
PBACS009: Acts with ethical responsibility in the areas of cybersecurity, intelligence, data protection, cyber crime, forensic investigation and cyber warfare taking into account the legal and deontological framework and the impact on individuals, organizations and society.
CodeDescription
PBACS009Acts with ethical responsibility in the areas of cybersecurity, intelligence, data protection, cyber crime, forensic investigation and cyber warfare taking into account the legal and deontological framework and the impact on individuals, organizations and society.
PBACS011: Directs its own professional development based on monitoring and consultation of relevant sources and practice-oriented research into (inter)national developments in cyber security and the domains that influence it with a view to lifelong learning.
CodeDescription
PBACS011Directs its own professional development based on monitoring and consultation of relevant sources and practice-oriented research into (inter)national developments in cyber security and the domains that influence it with a view to lifelong learning.

Omschrijving Onderwijsvorm (EN)

  • Lecture
  • Exercise class

Omschrijving Evaluatie (lijst) (EN)

Evaluation(s) for first exam chance
MomentForm%Remark
exam period 2 (2nd sem) (regular exam schedule)exam: specific method or combination of methods90,00
exam period 2 (outside exam schedule)non-period-bound evaluation: other method or combination of methods (Permanent evaluation)10,00
Evaluation(s) for re-sit exam
MomentForm%Remark
exam period 3 (august/september) (regular exam schedule)exam: specific method or combination of methods100,00