Web Application Security Fundamentals
Standard5 daysGroups from 5$35 a person
About this training
Find and fix the most common weaknesses in your own web applications.What you'll be able to do
- Recognise the OWASP Top 10 in real code
- Fix input-handling and access-control flaws
- Harden apps against browser-side attacks
- Build security checks into delivery
Outline
5 days of 2 h 10 min- Day 1How web apps are attackedHTTP, sessions and trust boundaries; The OWASP Top 10 at a glance.Lab: Map the attack surface of a sample app
- Day 2Input handlingValidating input; Parameterised queries; Safe file handling.Lab: Fix an unsafe database query
- Day 3Authentication and access controlSessions and password storage; Broken access control.Lab: Patch an access-control bug
- Day 4Browser-side risksCross-site scripting; Cross-site request forgery; Content Security Policy.Lab: Add output encoding and a CSP
- Day 5Secure deliveryDependency risk; Security logging; Security checks in CI.Lab: Add security checks to a pipeline
How it runs
- Live online, on the platform, at a time your group picks. In person at your office on request.
- Every session is recorded, so nobody misses anything.
- A certificate for everyone who completes the training.