Breaking Web Application Security Basics (FULL DAY)

No ratings

Presented at saintcon 2017 by

Have you ever wanted to know more about testing the security of a web application? Are you responsible for protecting a number of web sites for your employer, but don't know where to begin? And what's with all these acronyms such as CSRF, SQLi, XSS, and SSI? If you want to learn the basics of web application security and testing apps, then this class is for you! This course covers the different components of a websites, how they can be attacked, and how to protect them. Topics include testing for SQL injection, cross site scripting (XSS), cross site request forgery (CSRF), access controls, authentication and more. You will learn how to use a number of security tools to test for these issues, but the goal is for you to understand the issues rather than be tool dependent. By the end of the course you should have a foundational understanding of: * web app vulnerabilities * techniques for finding vulnerabilities * exploiting web app flaws * how to make recommendations to fix them To take this course, you will need * a laptop with at least 4 GB of RAM (8 GB would be better) * already installed virtualization software such as VMware Player/Workstation/Fusion or Virtual Box * a SamuraiWTF virtual machine already running on your laptop