Kõik koolitused ühest kohast!

tk
Tagasi

Web Application Security (WAS)

Web Application security essentials (4 parts, 8 lectures with practical demos and exercises for each vulnerability, including complex attack scenarios)

Ideology of this training
This training focuses on attacks so that the need for defence is better understood. OWASP project should be the bible of everyone dealing with WebApp development and security and OWASP ASVS (Application Security Verification Standard) is one of the golden standards of WebApp security testing. This training will cover all WebApp attack types and instills this knowledge with lot of hands-on exercises. With first-hand experience in those attacks, participants are better armed with understanding the attacks and why they are conducted.

Target audience:
WebApp developers, maintainers, web server or hosting providers/administrators, information security specialists and managers, testers

Program:

  • Client-Side attacks
    • Introduction, Client-Server system
    • OWASP (Top 10, ASVS)
    • Input data
    • GET vs POST
    • HTTP vs HTTPS
    • Controlling the thick client (Java applet, Flash, etc.,)
    • XSS (Cross-Site-Scripting)
    • Session security, cookies, session hijacking
    • OSRF/CSRF (On-Site and Cross-Site Request Forgery)
    • UI Redress Attacks (inc ClickJacking, CursorJacking)
    • Combined client side attacks
  • Server-Side attacks
    • Password security, crypto, brute-force, dictionary, sensitive data
    • Authentication and authorization errors, “remember me” features
    • Business logic implementation errors
    • Direct Object Reference mistakes
    • SQL injection
    • Code and Command injection
    • source code and structure defence, attack code upload, configuration
    • File handling (file extensions, public folder, execution, enumeration and quessing, meta info)
    • File inclusion (LFI, RFI, RCE, NULL-Byte)
    • File upload
    • Other file insertion vectors (log files)
    • Configuration (Java/PHP, error messages (what to show & what to log), Apache, file permissions)
    • Google hacking

All attacks have hands-on demos, exercises and “lessons learned” from our pentesting services.

Training methods:
Trainers will engage participants with lectures, live attack demonstrations and practical examples followed by individual hands-on exercise scenarios. Training is interactive, practical, and besides active participation also full of attack stories that help to change the perspective and understanding of real life security threats.

Ideology of this training:
This training focuses on attacks so that the need for defence is better understood. OWASP project should be the bible of everyone dealing with WebApp development and security and OWASP ASVS (Application Security Verification Standard) is one of the golden standards of WebApp security testing. This training will cover all WebApp attack types and instills this knowledge with lot of hands-on exercises. With first-hand experience in those attacks, participants are better armed with understanding the attacks and why they are conducted.

Trainer:
Marko Johani Belzetski
Marko holds a bachelor in business administration from Northwood University and is currently obtaining a degree in IT Systems Development from Estonian Information Technology College. Although his previous work experience has mainly been in finance and business support, he has also done freelance web application development.

Küsin koolituse kohta lisainfot

Koolitusfirma tutvustus

BCS Koolitus on Eesti juhtiv IKT valdkonna koolitus-, projektijuhtimis- ja konsultatsiooniettevõte. Loen koolitusfirma kohta veel...

Osalen koolitusel

Web Application Security (WAS)

NB! Hetkel ei ole koolitusel aktiivset toimumisaega.
Kui soovid, et teavitaksime Sind, kui see või mõni sarnane koolitus taas toimumas on, siis palun jäta meile oma kontaktandmed ja täpsem soov.
Soovin teavitust kuni kuu jooksul.