|
Csoport:
Rational Security and compliance
|
|
Kód:
RT330
|
|
Tanfolyam neve:
Essentials of Web Application Security V2.0
|
|
Időtartama:
1 nap
|
|
Netto ár Ft/fő (+ÁFA):
72000
|
|
Vizsgakód:
|
|
Leírás:
This course is designed to educate Web developers, security auditors, and quality assurance personnel about the Web application security problem. You will learn about the most critical Web application security vulnerabilities and ways to resolve them, as well as some best practices for integrating Web application security in the software development lifecycle (SDLC).
|
|
Cél:
Describe the Web application security problem
Understand secure coding concepts
Describe the Web Application Security Consortium (WASC) Threat Classifications
Describe the Open Web Application Security Project (OWASP) Top Ten Web application security vulnerabilities
Understand how simple exploits can be made
Implement solutions to the discussed vulnerabilities
Understand how Web application vulnerability testing can be implemented in the Software Development Life Cycle (SDLC)
Understand how you can use threat modeling techniques such as DREAD (Damage, Reliability, Exploitability, Affected users, and Discoverability) and STRIDE (Spoofing, Tampering, Repudiation, Information disclosure, Denial of service, and Elevation of privilege) to help you identify and prioritize Web application vulnerabilities
|
|
Kiknek ajánljuk:
This basic course is for:
- Web Developers
- Web Development Managers
- Quality Assurance Specialists
- Security Auditors
|
|
Előfeltétel:
You should have:
- Basic Web development knowledge
- Hypertext Markup Language (HTML)
- Hypertext Transfer Protocol (HTTP)
|
|
Tematika:
The Web Application Security Problem
Web Application Basics
Common Secure Coding Concepts
Cross-Site Scripting (XSS) and Cross-Site Request Forgery (CSRF)
SQL Injection
Malicious File Execution and Insecure Direct Object Reference
Information Leakage and Improper Error Handling
Broken Authentication and Session Management
Insecure Cryptographic Storage and Insecure Communications
Failure to Restrict URL Access
Integrating Application Security in your SDLC
|
|
Egyéb adatok:
A képzést megfelelő létszám esetén, igény szerint indítjuk. Kérjük, keresse tanfolyamszervezőnket!
|
|
Kapcsolatok:
|
Időpontok:
|