Skip to content
UdemyHackingPaid courseAll LevelsCertificate

Web security: Injection Attacks with Java & Spring Boot (Udemy.com)

Ethical Hacking, Web Application & Spring Security - Master Injection Attacks with NoSQL, LDAP, LOG, CSV & SQL Injection

Created by: Ali Gelenler

Last updated November 2025

icon
What you will learn

  • Ethical hacking with injection attacks
  • Web security
  • Secure coding
  • SQL Injection with PostgreSQL
  • NoSQL Injection with MongoDB
  • LDAP Injection with OpenLDAP
  • LOG Injection
  • CSV Injection
  • Spring security Form login authentication
  • Spring Data JPA
  • Spring Data MongoDB
  • Spring LDAP
  • Spring Validation

icon
Course Description

Are you a Java web developer and want to write secure code? Do you want to learn Ethical hacking and Web application security?  With this hands-on injection attacks course you will start learning web security using one of the top vulnerabilities of OWASP Top 10 list. Injection attack is still listed in top 3 attacks in the OWASP Top 10 and it is important to prevent against injection attacks to develop secure web applications.


  • Krzysztof Telka: "Nice examples, where the host is presenting step by step how to exploit the application and then how to prevent. Lot of nice tools, features to check and examine the web page in case of hackers attack. CSV/Log4J/SQL made big wow effect on my face. The atendeers they will not be dissapointed Great job Ali, Thank you!"

You can always use the latest versions for spring boot, and other dependencies in this course. I will be constantly updating the dependency version in the last section's lectures. You may check that to see the required code and configuration changes for updated versions. Also if you would like to use subtitles during the course, you can turn on the captions on videos. I suggest using subtitles to make it easier to follow the lectures.

As part of the blue and red security teams,I have a practical knowledge and I am here to help you learn the injection vulnerability in detail

In this course, you will focus on different type of injection attacks;

  • SQL Injection

  • NoSQL injection

  • LDAP injection

  • LOG injection

  • CSV injection

Ethical hacking and Web application security are the two important subjects of Cyber Security field and having practical knowledge about Injections will enable you to better understand the security concepts and make a quick start.

In this course you will follow defense-in-depth principle and apply multiple solutions to each vulnerability to secure the web application in multiple layers.

You will follow a hands-on approach. You will not only learn how to exploit an application using different kind of injection attacks, but also develop the vulnerable applications from scratch in which you will have a common web login module with Thymeleaf and Bootstrap for a basic front-end, with Spring security form login authentication & authorisation, and with separate applications for SQL, NoSQL and LDAP injections. 

The applications will be developed using Java, Spring boot and Spring Data along with the most used data sources, such as PostgreSQL for SQL Injection, MongoDB for NoSQL injection and OpenLDAP for LDAP injection.

In each section there will be;

  • Development of the vulnerable web application using Java, Spring boot and Spring security

  • Hacking of the application with various attack payloads and with Ethical hacking examples

  • Protection steps and the implementations to prevent injection attacks

At the end of the course you will understand the different type of injection vulnerabilities, perform injection attacks against the vulnerable web applications you have developed, and learn how to protect your applications against the injection attacks using various techniques such as,

  • Validation and sanitisation using white list approach

  • Parametrised queries with prepared statements

  • Escaping output

  • Using secure trusted libraries

  • Error handling and logging

  • General coding practices

If you want to skip the development and only perform the hacking of applications, you can jump into the injection lectures and download the source code provided in the resources section of that lecture. The source codes are in lecture 20 (SQL Injection), lecture 38 (NoSQL Injection), lecture 51 ( LDAP Injection), lecture 60 (LOG Injection) and lecture 74 (CSV Injection). Be aware that you will still need to install PostgreSQL for SQL Injection, MongoDB for NoSQL injection and OpenLDAP docker container for LDAP injection. You can see how to install and configure these data sources in the beginning lectures of each injection section.


  • Manoj Singh: "Talented instructor and great course!!! Just a small suggestion, If you could add a chapter about "Broken Access Control" topic that will be a great help."

For more detailed information on the progress of this course, you can check the introductory video and free lessons, and if you decide to enroll in this course, you are always welcome to ask and discuss the concepts and implementation details on Q/A and messages sections. I will guide you from start to finish to help you successfully complete the course and gain as much knowledge and experience as possible from this course.

Remember! There is a 30-day full money-back guarantee for this course! So you can safely press the 'Buy this course' button with zero risk and join this learning journey with me.

icon
Udemy Discount

The discount is applied through our link. Open the course from here and Udemy's current promotional price is applied at checkout on most courses, no code to type.

Some courses are excluded from Udemy's promotions. If the price does not drop, clear your browser cookies and use the button again.

icon
Instructor Details

Ali Gelenler

Ali Gelenler, the founder of EA Algorithm, has been in the IT industry for 20 years, with hands-on experience in Software Engineer, Software Architect and Tech Lead positions. He holds a Master's degree in Computer Engineering and is highly experienced in Backend technologies in distributed environments, Performance optimizations, Java, Spring, Spring boot, Microservices, Architectural patterns, Web security, Database technologies, Cloud-based solutions, Kafka, Elasticsearch, AI engineering with Java and Spring AI.

He is currently working actively as a Senior Engineer and Technical Leader and has experience in the financial technology sector, content management sector, defense industry and government projects.

Ali also has a passion for teaching and mentoring and worked as an instructor in individual and group classes in various IT fields.

icon
More courses by Ali Gelenler

$94.99

$84.99

icon
More Hacking courses

$109.99

$27.99

$14.99

$84.99

$84.99

$11.99

icon
Reviews

4.7

414 ratings on Udemy

Select a bar to show only those reviews.Select the bar again to show every rating.

By Jose Santos Saavedra Rivera on 4/8/2026

The course is interesting, but I would like to dive deeper into technical topics such as hacking techniques beyond SQL injection.

By Maximilian Rolf Görlich on 1/27/2025

The spoken english in this course is atrocious. Now I can accept a thick accent if the course is good (later on that), but this isn't even an accent anymore, we have pronunciation errors like "usish" instead of "users" or "paramitrish" instead of "parameters". There are many subtitles available but the english ones are only generated, the generation algorithm is pretty good and even keeps up with him but still, having a speaker this bad you would expect them to at least provide their own subtitles. The course itself is passable. It is 95% implementation and 5% sales pitch. It lacks any dedicated theoretical lectures on how the attacks work and how they are prevented. All of this knowledge gets explained on the side while implementing the code. Combining a passable course with horrendes oral english doesn't allow for anything higher than 2 stars.

By Krzysztof Telka on 9/26/2022

Nice examples, where the host is presenting step by step how to exploit the application and then how to prevent. Lot of nice tools, features to check and examine the web page in case of hackers attack. CSV/Log4J/SQL made big wow effect on my face. The atendeers they will not be dissapointed Great job Ali, Thank you!

By Miguel Angel Santos Nieto on 9/3/2022

I think it has been a good course, although personally, I think that section 2 could have been shorter and could have added some image or pdf on how the different interfaces and classes are related. As for the language, I quite liked the diction and the subtitles are quite good, which has helped me to follow this course, which is made in a language in which I am not fluent.

By Ozan Ilhan on 7/7/2022

Great course on web security. So far, I have learned a lot of valuable information. I would definitely recommend it.

By Manoj Singh on 5/15/2022

Talented instructor and great course!!! Just a small suggestion, If you could add a chapter about "Broken Access Control" topic that will be a great help.

By Arda Burak Ekmekçi on 3/29/2022

It is a great course for anyone who wants to start web security with a focus on injection vulnerability. Also there is a lot of hands on experience with separate projects and goals such SQL Injection, No-SQL Injection.

By Efe Kahraman on 3/21/2022

The course content covers almost everything and the instructor explains every chapter in a very understandable way. Security in software developement is a very essential topic hence every professional Java developer should get this course.

By Surjith S on 1/18/2022

Though I had previous experience using Kali linux and SQL injections, this course provides a far real insight into injection attacks. The versatility of the trainer makes the course enjoyable. With a fair understanding of Java anyone can easily grasp the concepts mentioned in this course. Strongly recommend to whoever interested in ethical hacking or security in applications.

By Jovan Krička on 11/4/2021

Awesome course, very clear, concise and informative. Also quite some hands on material

Showing all 10 reviews on CourseDuck

Read all 414 reviews on Udemy

icon
Quality Score

No CourseDuck member has rated this course yet. Taken it? Give each part a thumbs up or down.

Content Quality
/
Video Quality
/
Qualified Instructor
/
Course Pace
/
Course Depth & Coverage
/

Overall Score : 94 / 100