Skip to content

Web Application Security Fundamentals

Standard5 daysGroups from 5$35 a person

About this training

Find and fix the most common weaknesses in your own web applications.

What you'll be able to do

  • Recognise the OWASP Top 10 in real code
  • Fix input-handling and access-control flaws
  • Harden apps against browser-side attacks
  • Build security checks into delivery

Outline

5 days of 2 h 10 min
  • Day 1How web apps are attackedHTTP, sessions and trust boundaries; The OWASP Top 10 at a glance.Lab: Map the attack surface of a sample app
  • Day 2Input handlingValidating input; Parameterised queries; Safe file handling.Lab: Fix an unsafe database query
  • Day 3Authentication and access controlSessions and password storage; Broken access control.Lab: Patch an access-control bug
  • Day 4Browser-side risksCross-site scripting; Cross-site request forgery; Content Security Policy.Lab: Add output encoding and a CSP
  • Day 5Secure deliveryDependency risk; Security logging; Security checks in CI.Lab: Add security checks to a pipeline

How it runs

  • Live online, on the platform, at a time your group picks. In person at your office on request.
  • Every session is recorded, so nobody misses anything.
  • A certificate for everyone who completes the training.
Sample syllabus.