On Saturday, October 18th, 2025, OWASP Ottawa conducted the "Pentest 101" workshop.
The workshop was delivered by Chris Shepherd, an important member of our volunteer team, and led 38 attendees through the lifecycle of a web application penetration test. Chris covered reconnaissance (gathering information about our target web application), testing security controls using browser and dev tools only (testing for SQL Injection), and then using ZAP proxy to intercept and replay requests to perform attacks such as XSS and SSRF. Chris also walked attendees through how to prepare a professional write-up for these findings so that technical and non-technical people can understand the details and impact of these findings.
OWASP Ottawa would like to officially thank our workshop sponsors for supporting this event (in no-particular order):
1. @uottawa Faculty of Engineering and the uOttawa-IBM Cyber range for providing the required infrastructure to host the event.
2. @owasp for providing the OWASP Juice Shop application used as the targeted web application and SWAG
3. Packetlabs for providing pizza and SWAG
4. DeviousPlan for providing beverages
Lastly, OWASP Ottawa would like to thank all the attendees for attending this workshop and the volunteers who dedicated their time to make this workshop a success.
If you would like for OWASP Ottawa to organize more such workshops, please leave a comment below indicating what workshops you would like us to organize.







