OWASP Top 10 Essentials

Tijdsduur

OWASP Top 10 Essentials

OpenValue
Logo van OpenValue

Tip: meer info over het programma, prijs, en inschrijven? Download de brochure!

Startdata en plaatsen
Er zijn nog geen startdata bekend voor dit product.

OpenValue biedt dit product standaard aan in de volgende regio's: Amsterdam, Arnhem, Rotterdam, Utrecht

Beschrijving

Introduction
OWASP is a worldwide organization focused on improving software security. For this goal they have built a list of the top 10 most Critical Web Application Security Risks. In this workshop we will go through the list, focus on the risks important to your application and get some hands-on action by performing these exploits yourself.

Detailed description
The first part of the training will be an introduction into OWASP and their top 10. Next you will get the first assignments to get familiar with the online environment and the tasks to complete.

The main part of this course is then going to be a lot of fun. In an actual competition you are challenged to find and exploit vulnerabil…

Lees de volledige beschrijving

Veelgestelde vragen

Er zijn nog geen veelgestelde vragen over dit product. Als je een vraag hebt, neem dan contact op met onze klantenservice.

Nog niet gevonden wat je zocht? Bekijk deze onderwerpen: OWASP, Ethical Hacking, Cyber Security, Penetration testing en Identity Management & Access Control [IAM].

Introduction
OWASP is a worldwide organization focused on improving software security. For this goal they have built a list of the top 10 most Critical Web Application Security Risks. In this workshop we will go through the list, focus on the risks important to your application and get some hands-on action by performing these exploits yourself.

Detailed description
The first part of the training will be an introduction into OWASP and their top 10. Next you will get the first assignments to get familiar with the online environment and the tasks to complete.

The main part of this course is then going to be a lot of fun. In an actual competition you are challenged to find and exploit vulnerabilities. The trainer will coach the attendees and the platform will hint the trainees on how to find weak spots. However: each hint will cost you points. This playful approach has proven to be an excellent way to think as an attacker and learns them to understand where these spots arise. This of course will help them design more safe applications in the future.

And finally you will compete with your fellows to get the highest score by completing increasingly difficult hacking challenges.

Target audience
This training is suitable for everyone who would like to know about web application vulnerabilities and how they work in practice. It is not required to be a software developer, but you should be somewhat comfortable with the developer console of the web browser.

Learning goals

  • OWASP and the OWASP top10.
  • Exploiting web app security vulnerabilities.
  • Becoming more aware of security in software development.

Skills acquired in this training

  • Performing attacks like:
    • Cross-site scripting
    • Cross-site request forgery
    • SQL injection
  • Exploiting vulnerabilities like:
    • weak crypto
    • security misconfiguration
    • vulnerable default configuration

Topics

  • Attacks & vulnerabilities described in the previous section
  • Tooling for development and pipelines to detect potential vulnerabilities earlier
  • Preventing vulnerabilities from requirements

Training outline

  • Introduction/OWASP/top10 (1 hr)
  • Getting familiar with the platform (30 min)
  • Competition with the following aspects:
    • XSS
    • CSRF
    • SQL Injection
    • Exploiting Security misconfigurations
    • Exploiting weak cryptographic storage
    • Reverse engineering

The challenges will start off easier and gradually get more difficult. The first challenges will take a couple of minutes to track down and exploit, the harder challenges can take 30 minutes or more to solve.

Provided training material
Access to the platform during training.

About the trainer
Frank Walinga is a Software Engineer at OpenValue and focuses on Java and Security Awareness.

Note: This training can be given in Dutch or English at one of the OpenValue offices (Utrecht, Amsterdam, Rotterdam, Arnhem, Munich, Dusseldorf, Vienna, Zurich) or at your own location. Please contact us to discuss possibilities for a remote training and for training in German.

OpenValue Training - By Developers, For Developers. Learn from industry-leading software experts, Java Champions, and international conference speakers. Our 70+ hands-on IT courses cover modern tech stacks, software architecture, and best practices. Delivered by active software experts who apply what they teach daily on their innovative projects. Available in-company, at our offices, or online. Better Software, Faster starts with better training.

Blijf op de hoogte van nieuwe ervaringen
Er zijn nog geen ervaringen.
  • Vraag informatie aan over deze workshop. Je ontvangt vanaf dan ook een seintje wanneer iemand een ervaring deelt. Handige manier om jezelf eraan te herinneren dat je wilt blijven leren!
  • Bekijk gerelateerde producten mét ervaringen: OWASP.
Deel je ervaring
Heb je ervaring met deze cursus? Deel je ervaring en help anderen kiezen. Als dank voor de moeite doneert Springest € 1,- aan Stichting Edukans.

Er zijn nog geen veelgestelde vragen over dit product. Als je een vraag hebt, neem dan contact op met onze klantenservice.

Vraag nu gratis en vrijblijvend informatie aan:

(optioneel)
(optioneel)
(optioneel)
(optioneel)
(optioneel)
(optioneel)

Aanmelden voor nieuwsbrief

We slaan je gegevens op, en delen ze met OpenValue, om je via e-mail en evt. telefoon verder te helpen. Meer info vind je in ons privacybeleid.