Web Application Security Training
Introduction
Today most of the applications are web based including applications providing access to the corporate information which may be public or confidential. Organizations have invested a lot on protecting their infrastructure but now the attackers have turned attention over the web application for which the traditional protection mechanisms are not sufficient. The number of web application attacks is increasing every day and so are the business processes moving increasingly towards web services.
This training brings awareness of common web application vulnerabilities and the impact they have on your business. You will also learn effective defense mechanisms and security best practices to counter the web application attacks
Duration
3 Days
Who Should Attend
Anyone responsible for securing the infrastructure, penetration testers, security analysts, developers and anyone interested in understanding the web application concerns
Prerequisites
Familiarity with web technologies and information security
What Will You Learn
- Identify and understand areas of risk in web applications
- Assessing existing web applications
- Reduce vulnerabilities and extra development cycles for security fixes - Security professionals gain valuable insight to application layer security
- Increasing Application Security Awareness for Managers and Developers
- Protecting Revenue and Reputation of the organization
Contents
- Introduction to Web Technologies
- Authentication and Application Access Control
- Broken Account and Session Management
- Web Certificates and Secure Socket Layer
- General Input Validation
- Unicode Exploits
- Introduction to SQL Injection, Attack Samples and Database Structure
- Detecting SQL Injection
- Blind SQL Injection
- SQL Injection Mitigation and Vulnerability Testing
- Cross Site Scripting (XSS)
- Buffer Overflows
- Command Injection Flaws
- Denial of Service
- Web and Application Server Misconfiguration
- Web Services Attack Patterns
- Web Application Security Assessment
- Web Application Firewalls and IPS
- Web Server Modules
Hands-on
Live demonstrations and concept examples using the following:
- Webgoat
- Hackme bank
- Metasploit
- Webinspect
- Modsecurity
- IIS lockdown
- Nikkto