ISEC 3340 · OQF Level 7
Application Security
A hands‑on, lab‑first course on how web applications get attacked and how to defend them, built for Junior/Senior‑level students at Modern College of Business and Science, Muscat.
Overview
What the course covers
ISEC 3340 introduces students to the offensive and defensive sides of web‑application security. The syllabus and delivery plan are prepared in‑house, aligned with the Oman Qualifications Framework (OQF Level 7) and current industry practice, and every topic is anchored to a lab exercise rather than left as theory.
Students move from reconnaissance and common vulnerability classes through to responsible‑disclosure ethics and the legal framework around cybersecurity, finishing with an industry‑aligned project statement.
Tools students use
- OWASP Juice Shop: deliberately vulnerable app for guided exploitation labs
- Burp Suite: intercepting proxy for request tampering and analysis
Hands‑on labs
How the course is delivered
Each unit pairs a vulnerability class with a guided lab in a controlled environment.
Guided, instructor‑supervised exploitation exercises against OWASP Juice Shop, covering the vulnerability classes students are most likely to meet in real applications.
- SQL injection: identifying and exploiting unsanitized query inputs
- Cross‑Site Request Forgery (CSRF): how forged requests bypass session trust, illustrated with a controlled, ethics‑bound case study of a real‑world site under strict educational framing
- Brute‑force attacks: authentication weaknesses and rate‑limiting defenses
- Detailed discussion of CAPTCHA versions and their bypass/limitation trade‑offs
- General discussion on AI‑based cyber attacks and how generative tooling changes the threat model
- Discussion of cyber law, AI‑driven cyber‑attacks, and professional ethics
- Guest lectures delivered by practicing security experts
- Industry‑aligned capstone project statement
More courses
Other courses in progress
Computer Forensics
ISEC 4330 · OQF Level 8
Autopsy, FTK Imager, EnCase and Wireshark, taught through case‑based investigations.
System Programming & Tools
COSC 2350 · OQF Level 6
Virtual Linux labs with Strace and GDB.
Back to the full list
See every course and semester I've taught, plus curriculum work.
Go to Teaching