logo-img
(Web)Application Security Assessment - Based on OWASP Testing Guide

(Web)Application Security Assessment - Based on OWASP Testing Guide

4 days Classroom Nederlands

Sharpest price in just 2 steps

Requesting more information and/or the current price of this training is easy. We take into account any ongoing promotions, subsidies, or relationship discounts.

Description

In this training, you will learn the approach and techniques for conducting and understanding a pentest on specific (web) applications as described in the OWASP Testing Guide. All steps to be taken will be covered through challenging labs, from scope definition to the final reporting. In addition to the OWASP Top 10, you will also learn to test for lesser-known vulnerabilities.

The goal of this offensive training is twofold:

  1. To create a better awareness of the vulnerabilities in (web) applications by hands-on experiencing how these can be attacked/exploited by malicious actors;
  2. To teach participants to independently penetration test (web) applications using specifically designated open source tools or to better understand how an external penetration tester does this.

Legal Agreement:

The mission of the course "Application Security Assessment" is to educate, introduce, and demonstrate application security assessment techniques for penetration testing purposes only.

Prior to attending this course, you will be asked to sign an agreement stating that you will not use the newly acquired skills for illegal or malicious attacks and you will not use such tools in an attempt to compromise any computer system without the approval of the legal owner.

Working method

During this four-day course, the method and execution of a security assessment on a (web) application will be taught through hands-on examples and labs, using the OWASP Testing Framework.

All labs will be conducted with open source tools with a low 'click-here' factor, such as those available via the OWASP Web Testing Environment (WTE), OWASP Mantra projects, and Kali Linux.

Certification

This training is not associated with any exam or certification. Participants will receive a certificate of attendance that is suitable for maintaining a CEH or CISSP certification, for example.

Training Requirements

  • Voor deelname aan de WASA training is basiskennis van de bekende kwetsbaarheden van web applicaties noodzakelijk.
  • Kennis van het HTTP protocol, SQL en basis scripten.
  • Kennis van verschillende applicatie security scanners en tooling voor het vinden van kwetsbaarheden is niet noodzakelijk maar wel een pre.
  • Dit houdt voor oud-CEH deelnemers concreet in dat de onderwerpen met overlap als korte opfrisser worden behandeld of diepgaander zijn toegespitst op (web)applicaties.

Training Content

Information gathering

Configuration and deployment management testing

Identity management testing

Authentication testing

Authorization testing

Session management testing

Input validation testing

Error handling

Cryptography

Business logic testing

Client-side testing

API testing

Description

In this training, you will learn the approach and techniques for conducting and understanding a pentest on specific (web) applications as described in the OWASP Testing Guide. All steps to be taken will be covered through challenging labs, from scope definition to the final reporting. In addition to the OWASP Top 10, you will also learn to test for lesser-known vulnerabilities.

The goal of this offensive training is twofold:

  1. To create a better awareness of the vulnerabilities in (web) applications by hands-on experiencing how these can be attacked/exploited by malicious actors;
  2. To teach participants to independently penetration test (web) applications using specifically designated open source tools or to better understand how an external penetration tester does this.

Legal Agreement:

The mission of the course "Application Security Assessment" is to educate, introduce, and demonstrate application security assessment techniques for penetration testing purposes only.

Prior to attending this course, you will be asked to sign an agreement stating that you will not use the newly acquired skills for illegal or malicious attacks and you will not use such tools in an attempt to compromise any computer system without the approval of the legal owner.

Working method

During this four-day course, the method and execution of a security assessment on a (web) application will be taught through hands-on examples and labs, using the OWASP Testing Framework.

All labs will be conducted with open source tools with a low 'click-here' factor, such as those available via the OWASP Web Testing Environment (WTE), OWASP Mantra projects, and Kali Linux.

Certification

This training is not associated with any exam or certification. Participants will receive a certificate of attendance that is suitable for maintaining a CEH or CISSP certification, for example.

Training Requirements

  • Voor deelname aan de WASA training is basiskennis van de bekende kwetsbaarheden van web applicaties noodzakelijk.
  • Kennis van het HTTP protocol, SQL en basis scripten.
  • Kennis van verschillende applicatie security scanners en tooling voor het vinden van kwetsbaarheden is niet noodzakelijk maar wel een pre.
  • Dit houdt voor oud-CEH deelnemers concreet in dat de onderwerpen met overlap als korte opfrisser worden behandeld of diepgaander zijn toegespitst op (web)applicaties.

Training Content

Information gathering

Configuration and deployment management testing

Identity management testing

Authentication testing

Authorization testing

Session management testing

Input validation testing

Error handling

Cryptography

Business logic testing

Client-side testing

API testing

shape

I am taking this next step in my lifelong learning journey.

1

Applicant Information

2

Billing Information

What Can I Learn After The (Web)Application Security Assessment - Based on OWASP Testing Guide?

  • Creating a better awareness of the vulnerabilities in (web) applications by hands-on experiencing how they can be attacked/abused by malicious actors;
  • Teaching participants to independently penetration test (web) applications using specifically designated open source tools or to better understand how an external penetration tester does this.

Schedules

This training is scheduled as follows in the coming period. Missing a date? Feel free to contact us.

Date: In overleg

Location: TSTC Veenendaal - Klassikaal

1

Applicant Information

2

Billing Information

Learning paths

This training can also be taken as part of the below learning path(s). If you want to follow multiple titles from a learning path, please contact our advisors for a suitable bundle offer.

I am taking this next step in my lifelong learning journey.

1

Applicant Information

2

Billing Information

Why experienced professionals choose TSTC for their studies

Train smarter, not harder. TSTC's unique approach guarantees the effective acquisition of skills and the greatest chance of success.

Learn more about TSTC
Toucan Rhino