July 25, 2026
Week 4 of My Thunder Cipher Cybersecurity Internship: Diving Deep into Web Application Security
Cybersecurity isn’t just about knowing vulnerabilities — it’s about understanding why they exist, how they’re exploited in controlled…

By cyb3rPh03n1x
3 min read
Cybersecurity isn't just about knowing vulnerabilities — it's about understanding why they exist, how they're exploited in controlled environments, and most importantly, how they can be prevented.
Week 4 of my Thunder Cipher Cybersecurity Internship was entirely focused on Web Application Security. It was my most practical week so far, combining theoretical concepts with hands-on labs across Thunder Cipher Labs, TryHackMe, PortSwigger Web Security Academy, and DVWA.
Throughout the week, I explored the OWASP Top 10 (2025), access control vulnerabilities, Linux privilege escalation, reconnaissance techniques, SQL Injection, Cross-Site Scripting (XSS), Server-Side Request Forgery (SSRF), and cryptographic failures while gaining practical experience using industry-standard tools.
📅 Day 12 — Understanding OWASP Top 10
The week started with an introduction to Web Application Penetration Testing (WAPT) and the OWASP Top 10 (2025).
Topics covered included:
- OWASP Top 10 (2025)
- OWASP Mobile Top 10
- Broken Access Control (A01)
- IDOR (Insecure Direct Object Reference)
- Privilege Escalation
- RBAC, MAC & DAC
- Gobuster
- Hydra
- CIA Triad
- Website Security Checker
The practical highlight of the day was solving the Thunder Cipher "DeleteMe" Lab, where I learned how authorization flaws such as Broken Access Control and IDOR can allow unauthorized actions when applications fail to validate user permissions.
🔐 Day 13 — Access Control & Linux Privilege Escalation
The second day focused on securing systems through proper authentication and authorization mechanisms.
Topics covered:
- IAAA Security Model
- Access Control Vulnerabilities
- Linux Privilege Escalation
- Referer-Based Access Control
- GTFOBins
- Wayback Machine
Hands-on activities included:
- TryHackMe Linux Privilege Escalation
- PortSwigger Referer-Based Access Control
The labs demonstrated how improper access control and Linux misconfigurations can create opportunities for privilege escalation and authorization bypass in vulnerable environments.
🛰️ Day 14 — Practical Penetration Testing
This session was dedicated to applying the penetration testing methodology using the Thunder Cipher Attack Box.
Activities included:
- Solving Thunder Cipher practical labs
- Beginning the TryHackMe Basic Pentesting room
- Reconnaissance
- Enumeration
- Linux Enumeration
- Web Enumeration
- Information Gathering
This session reinforced one of the most important lessons in penetration testing:
Good enumeration often leads to successful assessments.
Rather than immediately searching for vulnerabilities, we learned the importance of understanding the target environment first.
🌐 Day 15 — Vulnerability Research & OWASP Labs
The focus shifted towards understanding common web vulnerabilities and researching modern attack vectors.
Topics covered:
- TryHackMe OWASP Top 10
- Wappalyzer
- Exploit Database (Exploit-DB)
- Broken Access Control
- Cross-Site Scripting (XSS)
- A04 — Insecure Design
- A07 — Identification & Authentication Failures
- A08 — Software & Data Integrity Failures
- A10 — Server-Side Request Forgery (SSRF)
Using Wappalyzer, I learned how to identify technologies powering web applications, while Exploit Database introduced me to researching publicly disclosed vulnerabilities and proof-of-concept references.
💉 Day 16 — SQL Injection, XSS, SSRF & Cryptographic Failures
The final session of the week combined several practical web security labs.
Activities included:
- PortSwigger SQL Injection Authentication Bypass Lab
- Burp Suite Repeater
- DVWA Reflected XSS
- Basic SSRF Lab
- TryHackMe Cryptographic Failures Room
These exercises demonstrated how vulnerabilities such as SQL Injection, Cross-Site Scripting, and Server-Side Request Forgery arise due to insecure application design and improper input handling.
The Cryptographic Failures room highlighted the importance of implementing modern cryptographic standards to protect sensitive information.
🛠️ Tools & Platforms Explored
Throughout Week 4, I worked with several industry-recognized platforms and tools:
- Thunder Cipher Attack Box
- Thunder Cipher Labs
- TryHackMe
- PortSwigger Web Security Academy
- DVWA (Damn Vulnerable Web Application)
- Burp Suite Community Edition
- Gobuster
- Hydra
- Wappalyzer
- Exploit Database
- Wayback Machine
- GTFOBins
🎯 Key Takeaways
Week 4 significantly expanded my practical understanding of web application security.
Some of my biggest learnings include:
- Understanding the OWASP Top 10 (2025) through practical labs.
- Learning how Broken Access Control remains one of the most critical web vulnerabilities.
- Strengthening Linux privilege escalation fundamentals.
- Improving reconnaissance and enumeration techniques.
- Gaining hands-on experience with SQL Injection, XSS, SSRF, and Cryptographic Failures.
- Understanding secure authentication, authorization, and cryptographic implementation.
- Becoming more confident using Burp Suite for HTTP request analysis.
Most importantly, this week reinforced that effective penetration testing is driven by methodology, patience, and thorough analysis — not just running tools.
🚀 Looking Ahead
As I continue this internship, I'm looking forward to exploring more advanced web application security concepts, vulnerability assessment techniques, and real-world penetration testing scenarios.
Every practical lab continues to strengthen both my technical skills and my understanding of how secure applications are designed and defended.
GitHub Repository
I'm documenting my complete internship journey — including daily notes, practical labs, weekly summaries, and learning resources — on GitHub.
GitHub: https://github.com/glenjr009/thunder-cipher-cybersecurity-internship
Thank you for reading!
If you're also learning cybersecurity, feel free to connect and share your journey. Documenting my progress publicly has been a great way to reinforce concepts, build a technical portfolio, and track my growth as an aspiring cybersecurity professional.
LinkedIn:- https://www.linkedin.com/in/glen-ferns/