Web Application Security (WAS)

Training dates:
27th – 28th February and 6th – 7th March 2019

Contents of this training:

Web Application security essentials (4 parts, 8 lectures with practical demos and exercises for each vulnerability, including complex attack scenarios):

Client-Side attacks:
  • Introduction, Client-Server system
  • OWASP (Top 10, ASVS)
  • Input data
  • GET vs POST
  • HTTP vs HTTPS
  • Controlling the thick client (Java applet, Flash, etc.,)
  • XSS (Cross-Site-Scripting)
  • Session security, cookies, session hijacking
  • OSRF/CSRF (On-Site and Cross-Site Request Forgery)
  • UI Redress Attacks (inc ClickJacking, CursorJacking)
  • Combined client side attacks
Server-Side attacks:
  • Password security, crypto, brute-force, dictionary, sensitive data
  • Authentication and authorization errors, “remember me” features
  • Business logic implementation errors
  • Direct Object Reference mistakes
  • SQL injection
  • Code and Command injection
  • source code and structure defence, attack code upload, configuration
  • File handling (file extensions, public folder, execution, enumeration and quessing, meta info)
  • File inclusion (LFI, RFI, RCE, NULL-Byte)
  • File upload
  • Other file insertion vectors (log files)
  • Configuration (Java/PHP, error messages (what to show & what to log), Apache, file permissions)
  • Google hacking

* All attacks have hands-on demos, exercises and “lessons learned” from our pentesting services.

More information:

https://clarifiedsecurity.com/web-application-security-training/

Tähelepanu! Teie veebilehtiseja ei vasta kodulehe külastamiseks vajalikele nõuetele. Palun vahetage veebilehitsejat või seadet, millega te veebilehte sirvite.

Attention! Teie veebilehtiseja ei vasta kodulehe külastamiseks vajalikele nõuetele. Palun vahetage veebilehitsejat või seadet, millega te veebilehte sirvite.

Внимание! Teie veebilehtiseja ei vasta kodulehe külastamiseks vajalikele nõuetele. Palun vahetage veebilehitsejat või seadet, millega te veebilehte sirvite.