We provide virtual course about Masterclass: Web Application Pentesting in english. In this 3-day, 21-hour course, you will develop essential cybersecurity knowledge and skills with a focus on Web Application Pentesting.
Moreover, you will be able to:
• Get the highest quality and unique learning experience - the class is limited to 16 participants by default
• Get the opportunity to interact with our world-renowned Experts
• Go through CQURE’s custom lab exercises and practice them after the course
• Receive a lifelong certification after completing the course
• Get 12-month access to the recordings
Why this course:
This course covers techniques and strategy concepts for performing professional web applications penetration testing in a highly secure environment. Our course has been developed around professional penetration testing, web applications development and security awareness in the business and IT fields.
Our goal is to show you all the most important aspects of web application penetration testing. Together we will look for vulnerabilities and exploit them in practice in CQURE’s custom-built training environment. During the exercises, we will use industry-standard tools such as the Kali Linux, Burp Suite, Bloodhound, Metasploit and the Wireshark.
Course outline:
The Web Application Pentesting agenda consists of 10 modules that will be covered during 3 days. The training will allow you to understand the penetration tester’s perspective on security, and learn crucial tools and concepts needed for everyone considering developing their career in penetration testing or cybersecurity in general.
Agenda:
Module 1 - Introduction to Web Penetration Testing:
• What is Penetration Testing
• Cyber Kill Chain
• MITRE ATT&CK Matrix
• Testing methodologies
• Reporting
Module 2 - Reconnaissance:
• Open-Source Intelligence (OSINT)
• Google hacking and alternative search engines
• Subdomains and DNS enumeration
• Discovering hidden secrets
Module 3 - Introduction to Web Application testing:
• OWASP TOP 10
• Role of local-proxy
• Work automatization
• Business logic issues
• Supply chain attacks and vulnerable components
• Chaining security issues
• Information disclosures
Module 4 - Browser's security mechanisms:
• Same Origin Policy
• CORS and other exceptions
• 3rd party cookies
• Security headers
• Content Security Policy (CSP)
• Cookies’ and local storage security
Module 5 - Cross Site Scripting:
• Reflected and Stored Cross Site Scripting
• Attacking Document Object Model
• Bypassing weak CSP
Module 6 - Injections:
• Blacklisting vs whitelisting
• SQL injections
• Command injections
• Other injection attacks
Module 7 - Authentication and Authorization:
• Attacks on authentication and authorization
• Attacks on sessions
• Insecure Direct Object Reference (IDOR) attacks
• Default credentials
• JSON Web Tokens
Module 8 - Insecure file handling:
• Path traversal
• Content manipulation
• Insecure file extensions
Module 9 - Insecure inclusions:
• Local File Inclusion
• Remote File Inclusion
Module 10 - Testing API:
• OWASP Top 10 for API
• Bypassing API access controls
• Mass assignment attacks
Target audience:
This bootcamp is designed for you if you are a:
• Penetration tester
• Security analyst
• IT administrator
• Cybersecurity professional
• & a geek with IT background who wants to start an adventure in the cybersecurity pentesting field
Language:
• English course material, english speaking instructor
Course material:
The course fee includes lab exercises, course materials and certification
Certification:
After finishing the course, you will be granted a CQURE Certificate of Completion. Please note that after completing the course you will also be eligible for CPE points!