I suggest you start by having a look at the OWASP Top 10 and the OWASP Testing guide.
Also read the Web Application Hackers Handbook 2nd Edition and learn how to use Burp Suite Pro.
I personally have not taken GWAPT so cannot comment on it, but the OSCP certification from Offensive Security is well regarded.
I suggest you start by having a look at the OWASP Top 10 and the OWASP Testing guide. Also read the Web Application Hackers Handbook 2nd Edition and learn how to use Burp Suite Pro.
I personally have not taken GWAPT so cannot comment on it, but the OSCP certification from Offensive Security is well regarded.
Good luck