Pwning Web Apps – An Intro to Web App Pentesting

No ratings

Presented at Texas Cyber Summit 2023 by

NEEDED: Hardware requirements for the virtual lab: Laptop with 20GB for free disk space VirtualBox or VMWare is required to run the virtual lab Web applications have become the most popular and widely used application type due to portability and compatibility, and these attributes have made them widely used for businesses of all sizes. Web application security and the assessment of security is often misunderstood, overlooked, or just ignored. Web applications and websites accessible through the Internet can be a risk and, when not secure, can expose sensitive information and access to underlying IT infrastructure. The skills taught in this workshop are valuable to aspiring to become pentesters or security researchers and participate in bug bounties. Attendees will be provided with a virtual machine-based lab learning environment for use in the workshop and after to continue learning web app pentesting. Participants will receive a list of resources to further their study of web app pentesting. In this workshop, participants will learn about web application vulnerability assessments and web application pentests. Attendees will learn how to discover, validate, and exploit vulnerabilities from the OWASP Top 10 using industry-standard commercial tools and Free and open-source software (FOSS) following the OWASP Testing Guide. During the workshop, attendees will learn how to conduct a web application pentests and write a report on the findings and security posture of the web application. The following web app pentesting methodology steps will be covered during the workshop: • Pre-engagement Interactions • Intelligence Gathering • Threat Modeling • Vulnerability Analysis • Exploitation • Post Exploitation • Reporting