Specifications
| Format | Learning |
|---|---|
| Level | Beginner, Intermediate, Advanced |
| Price | Paid tier exists |
| Access | No registration |
| Activity | Active |
| Language | EN |
| Category | Web |
The web pentesting academy run by the makers of Burp Suite, working through the OWASP list topic by topic, from recon to business logic flaws. Practice happens in labs on deliberately vulnerable applications. Learning is free; the exam at the end is not.
Pros & cons
Pros
- Walks the full OWASP web list in an order that makes sense
- Labs annotate the request and response that actually matter
- Free and open: no account needed to reach any topic
Cons
- The certificate needs an active Burp Suite Professional subscription
- Web applications only, nothing on networks, Active Directory or binaries
- Community solutions are uneven: some labs have a dozen writeups, some have none
Who it fits
Suits anyone moving into web security: it closes the gap between knowing a vulnerability name and testing for it. Finish the whole path even without the exam.
Getting started
- Do Access Control and SQL injection first, they set up everything after them
- Solve each lab in Burp Suite Community, the paid licence is not needed
- Keep a table: vulnerability, where you met it, how you confirmed it
History
Grew out of PortSwigger Research writing and became the reference most web testers cite. New topics arrive as new bug classes surface in breach reports, so the syllabus tracks what is actually being exploited rather than a fixed curriculum.