Web App Attacks & Defense
Length of Course
1 day
Description
Web sites are constantly at risk of being hacked. It is likely that attackers are trying to find holes in your web applications, making it imperative that you find these issues before attackers discover and exploit them. Early detection is the key to protecting your reputation and customers, maintaining compliance, and reducing overall costs.This course is an introduction to some of the most common web application attacks in use today. Through hands on exercises, students learn how to identify common web application vulnerabilities and are introduced to penetration testing & ethical hacking techniques that you can use to proactively test your applications.
Once you find these issues what can you do? You will learn defensive techniques that can be used to protect your web application against future attacks. You will also learn best practices and principles that will help you incorporate security throughout the software development lifecycle.
Sampling of Topics
- XSS – Cross Site Scripting
- CSRF – Cross Site Request Forgery
- SQLi – SQL Injection
- Parameter Manipulation
- Data Validation Techniques
- Authentication/Authorization Bypass
- Session Management Issues
- Business Logic Flaws
- Configuration Flaws
Who Should Attend
- Web Application Developers
- QA Testers interested in security testing
- Application Architects interested in security issues
- IT Professionals who want an understanding of web application vulnerabilities
- Anyone interested in identifying and fixing web application vulnerabilities
Prerequisites
This is a hands on course. Students should be familiar with web applications and have an understanding of how they are developed and/or tested.
Laptop Requirements
Students are required to bring their own laptops that meet the following requirements:
Minimum hardware requirements
- 1GHz processor
- 512MB RAM (1GB recommended)
- DVD drive
- 5GB free hard disk space
VMWare
One of the following versions of VMWare is required:- VMWare Player 1.0 or later
- VMWare Workstation 6.0 or later
- VMWare Fusion
