Batch 01 · Applications Open · Free

Real Pentesting.
Real Reports. Real Experience.

A hands-on security training program where you attack real vulnerable web applications, write professional penetration testing reports, and get reviewed by an actual practitioner. No flags. No guided hints. No automated scoring.

Requires basic Burp Suite & manual testing knowledge  ·  Not for absolute beginners
What is DoPentest

The gap between a vulnerability scanner and a pentest.

A vulnerability scanner finds known CVEs. A penetration tester finds what the scanner misses — business logic flaws, broken access controls, and chained vulnerabilities that only make sense in context.

DoPentest trains the second skill. Every lab is built around vulnerabilities found during real security assessments — the same class of bugs that appear in professional pentest reports, not CTF competitions.

You are not scored on how many bugs you find. You are scored on whether your report would be useful to the client.

Everywhere else DoPentest
Goal

Capture the flag

Goal

Write a report the client can act on

Vulnerabilities

Planted flags, guided hints

Vulnerabilities

Real bugs from real engagements

Scoring

How many flags captured

Scoring

Quality of the report, not quantity of findings

Deliverable

Flag string or score

Deliverable

Professional PDF pentest report

Feedback

Automated / none

Feedback

Manual line-by-line review by a practitioner

The Difference

What this program actually trains.

These are not skills you pick up from tutorials. They come from doing the work under conditions that resemble the real thing.

01

No flags. No hints. No hand-holding.

The application has no flags to capture. There are no hints telling you where to look. You enumerate the surface, form hypotheses, and test them. You think like an attacker or you miss the finding.

02

Small bugs count. Document everything.

A low-severity information disclosure ships in real reports. An IDOR on a non-critical endpoint still gets documented. Completeness is a professional skill. Missing low findings is a reporting failure, not an acceptable gap.

03

Business impact, not just exploitation.

Showing alert(1) is not a finding. Demonstrating that the same XSS allows session hijacking on an authenticated admin panel — and explaining what data is at risk — is a finding.

04

Remediation guidance is required.

Clients don't pay for a list of vulnerabilities. They pay for a path to fix them. Every finding must include clear, actionable remediation steps. That is what separates a pentest report from a scanner output.

05

Real vulnerabilities from real assessments.

Every lab is built around vulnerability classes encountered during actual penetration tests — not theoretical textbook examples, not CVE reproductions. Business logic flaws, broken access controls, auth weaknesses. The bugs that scanners miss.

06

Passed on report quality, not finding count.

A report with three findings documented professionally — with full impact analysis, clear PoC, and actionable remediation — outscores a report listing ten findings with no context. This is how real engagements are evaluated.

Pass Criteria

How reports are evaluated.

There is no automated scoring. A practitioner reads every report manually and evaluates it against the same criteria used in actual client engagements.

You can find fewer vulnerabilities than other participants and still pass — if your documentation of those findings is professional, complete, and would genuinely help a developer remediate the issue. Quality of work matters more than quantity of findings.

Reproduction steps

Required

Clear, numbered steps that allow a developer to reproduce the issue from scratch. Screenshots and HTTP requests where relevant.

Business impact

Graded

What does this vulnerability mean for the business? Data exposure, financial risk, compliance implications, reputational damage. Stated in plain language, not technical jargon.

Severity rating with justification

Required

CVSS score or qualitative rating with a written justification. The rating must match the impact you've described.

Remediation guidance

Graded

Specific, actionable steps to fix the issue. Not "sanitize input" — how to sanitize, what library to use, what the secure pattern looks like.

Executive summary

Required

A non-technical overview of what was found, the overall risk posture, and the most critical issues — written for someone who will not read the technical details.

Training Batches

Structured. Time-bound. Reviewed.

Each batch runs for a fixed duration with a defined set of labs. Pass both labs to earn the batch completion certificate.

BATCH 01 Open
Web Application Penetration Testing — Fundamentals

Two vulnerable web applications with real business logic flaws, broken access controls, and authentication weaknesses. Each application is isolated to your own instance. Black-box — no source code, no hints.

Lab 01 — HR Portal Lab 02 — Full Simulation
Apply Now — Free
Pass both labs to earn the Batch 01 Completion Certificate
Duration15 Days
Labs2
FormatBlack Box
ReviewManual
CostFree
BATCH 02 Upcoming
Web Application Penetration Testing — Intermediate

More complex applications, more interacting vulnerabilities, higher bar for report quality. Details announced after Batch 01 closes.

Lab 01 Lab 02 Lab 03
DurationTBA
LabsTBA
FormatBlack Box
CostRs. 4,500
Who Should Apply

This is not for absolute beginners.

DoPentest assumes you already know the basics. The program trains professional execution — not foundational concepts.

You should apply if
+You can use Burp Suite for manual testing — intercept, modify, and replay requests
+You understand common web vulnerabilities: XSS, SQLi, IDOR, broken auth at a conceptual level
+You've done any CTF, PortSwigger labs, or similar hands-on practice
+You want to learn how to document and communicate findings professionally
+You're a CS or security student who wants something real to show an employer
Do not apply if
-You have never used Burp Suite or any proxy tool
-You are looking for step-by-step guided walkthroughs
-You expect hints when stuck — there are none
-You want to learn exploitation techniques from scratch
-You are not willing to write a full professional report for each lab
The Process

Apply. Get accepted. Start working.

STEP 01

Apply

Submit your application with background and experience. Every application is reviewed manually. You'll hear back within 48 hours.

STEP 02

Get accepted

Accepted participants receive the NDA, Scope of Work, and their dedicated lab URL — delivered directly. No dashboard. No setup.

STEP 03

Test and document

Attack the application within scope. Document every finding — complete with impact, reproduction steps, and remediation. Submit your PDF report before the deadline.

STEP 04

Get reviewed

A practitioner reads your report manually. You receive written feedback on every finding. Pass both labs and the completion certificate is yours.

FAQ

Common questions.

Is testing the lab application legal? +
Yes. Accepted participants receive a signed Scope of Work and NDA before the lab begins. You are fully authorized to test within the defined scope. Testing outside scope is a violation of the agreement.
What kind of vulnerabilities are in the labs? +
Business logic flaws, broken access controls, authentication weaknesses, stored XSS, IDOR, and similar vulnerabilities commonly found during real web application penetration tests. The exact findings are not disclosed. You discover them through enumeration and manual testing.
Can I pass if I find fewer bugs than others? +
Yes. Passing is based on the quality of your report, not the number of findings. A report with two findings documented to a professional standard — full impact analysis, clear reproduction steps, actionable remediation — will outperform a report listing eight findings with no context.
What format should the report be in? +
PDF. There is no required template — you structure the report as you would for a real client. It must include an executive summary, individual finding sections with severity ratings, and remediation guidance. How you organize that is part of the assessment.
How long does the review take? +
Typically 2–4 days after submission. You receive written feedback on every finding in your report, regardless of pass or fail.
What does the completion certificate include? +
The certificate states that you completed the DoPentest batch, passed the report review for both labs, and demonstrates hands-on penetration testing and professional reporting skills. It is not an industry certification — it is proof of work you can show and explain.
Batch 01 · Free · Applications Open

Stop preparing.
Start doing.

Apply now. Get your scope doc. Find real bugs. Write a real report. Get reviewed by someone who has done this professionally.

Applications reviewed manually · Reply within 48 hours