Back To Schedule
Monday, January 25 • 9:00am - 5:00pm
OWASP Top 10 – Exploitation and Effective Safeguards

Sign up or log in to save this to your schedule, view media, leave feedback and see who's attending!

About the course 

The OWASP Top 10 web application vulnerabilities has done a great job promoting awareness for the developers. Along with many cheat sheets, they provide valuable tools and techniques to web developers. But such a great source of information could be overwhelming for the programmer who wants to learn about security. This course aims at providing all web developers deep hands-on knowledge on the subject.

To achieve this goal, participants will first learn the technical details about each OWASP Top 10 vulnerability. Then the instructor will give demos on how attacks are performed against each of them. After that, participants will use virtual machines and follow step by step procedures to launch attacks against a vulnerable web site. This step is key in understanding how exploitation works so they can later implement effective safeguards in their systems. Our experience is that participants who have had hands-on experience at exploiting vulnerabilities will always remember how to prevent them.

Who should take this course?

This course is designed to help intermediate to expert web developers and security professionals understand how to secure web applications. Candidates are expected to have basic knowledge of web technologies, but no experience in security is required prior to taking this course. However, security professionals who want to learn more about web security will benefit from this class.

The course will cover the following topics

1. OWASP Top 10 web application vulnerabilities:
    A1 - Injection Attacks
        Command Injection
        File Injection
        SQL Injection
    A2 - Broken Authentication and Session Management
    A3 - Cross-Site Scripting (XSS)
    A4 - Insecure Direct Object References
    A5 - Security Misconfiguration
    A6 - Sensitive Data Exposure
    A7 - Missing Function Level Access Control
    A8 - Cross-Site Request Forgery (CSRF)
    A9 - Using Known Vulnerable Components
    A10 - Unvalidated Redirects and Forwards
2. Proper Password Management
3. Secure Coding Best Practices
4. Effective Safeguards

Demos from the instructor

1.  SQL Injection Attack
2.  Cross-Site Scripting Attack
3.  Insecure Direct Object References
4.  Sensitive Data Exposure
5.  Cross-Site Request Forgery

Hands-on Exercises

1.  Session Initialization and Client-Side Validation       
      Part 1: Web Proxy and Session Initialization       
      Part 2: Client-Side Validation   
2.  Online Password Guessing Attack   
3.  Account Harvesting   
4.  Sniffing Encrypted Traffic   
5.  Launching Command Injection Attacks   
6.  Using a Web Application Vulnerability Scanner   
7.  Optional Exercise:
           Create SSL certificates


Participants are asked to bring a laptop (Windows, Mac or Linux) with at least 3 GB of RAM, 20 GB of free disk space and either VMWare Player (free), VMWare Workstation, VMWare Fusion or Oracle VirtualBox pre-installed. They must also have an administrator/root account on their laptop. At the beginning of the course, participants will receive a USB thumb drive containing two pre-configured virtual machines. 

avatar for David Caissy

David Caissy

Security consultant, Albero Solutions Inc.
David Caissy, OSCP, GWAPT, GPEN, GSEC, CISSP, CEH has 16 years of experience as a security consultant and a web application architect. He has performed security audits, vulnerability assessments, web application penetration tests and has designed several secure systems. He has worked... Read More →

Monday January 25, 2016 9:00am - 5:00pm PST
Annenberg Community Beach House

Attendees (1)