Description
Web Application Security Training And Certification
A Web Application Penetration testing or VA/PT Process will cover all the tools and top 10 owasp and Sans top 20 Critical vulnerabilities testing of a Web Application which is running on a web server. Vulnerabilities could occur in any kind of web Programming language like Asp, JSP,Java,Python and many more. So for a web application security expert it is necessary to understand all the latest vulnerabilities which could be there in a web application like SQL Injection, Php injection,cross site scripting, cross site request forgery, session hijacking and etc.
What will be Covered in the Web Application Security Training
1 : Sql Injections Flaws : Login Authentication Bypass,Blind Sql Injection Manual and Automated using Havij, SQLMAP, Html Injection.
2 : Cross Site Scripting Flaw : Reflected and Stored XSS using Manual and Tool Based : Using Burp Suite
3 : Source Code Disclosure Flaw : Manual Process and File Inclusion
4 : OS Command Injection Flaw: On DVWA (Damn Vulnerable Web Application) and Metasploitable
5 : Broken Authentication and Session Management : DVWA -Damn Vulnerable Web Application, Samurai OS
6 : File Upload Vulnerability (Dangerous File Upload) Live Practical Based Example
7 : CSRF – Cross Site Request Forgery
8 : Sensitive Data Exposure : Live Web Site
9 : Insecure Direct Object Reference: Instructor Special
10 : Local file Inclusion and Remote File Inclusion(LFI and RFI attack): BURP SUITE
11 : Directory Traversal Attack Traversing Directories on a Web Site
12 : Insecure Transport Level Communication: Weak SSL Version Detection
13 : Information Exposure Through an Error Message
14 : Invalid URL Redirection Flaw
15 : Hard-coded Credentials in Static Code
16 : Security Mis-Configuration
17 : Missing Authorization and Authentication for Critical Functions
18 : Session Fixation
19 : Weak Data Encryption
20 : Information Leakage
Curriculum
Course Outline will brief more about the modules covered in the Classroom or Online Training Sessions
Lecture1.1
SQL Injections Flaws
Lecture1.2
Cross Site Scripting Flaw
Lecture1.3
Source Code Disclosure Flaw
Lecture1.4
OS Command Injection Flaw
Lecture1.5
Broken Authentication and Session Management
Lecture1.6
File Upload Vulnerability (Dangerous File Upload)
Lecture1.7
CSRF – Cross Site Request Forgery
Lecture1.8
Sensitive Data Exposure
Lecture1.9
Insecure Direct Object Reference
Lecture1.10
Local file Inclusion and Remote File Inclusion(LFI and RFI attack)
Lecture1.11
Directory Traversal Attack
Lecture1.12
Insecure Transport Level Communication
Lecture1.13
Information Exposure Through an Error Message
Lecture1.14
Invalid URL Redirection Flaw
Lecture1.15
Hard-coded Credentials in Static Code
Lecture1.16
Security Mis-Configuration
Lecture1.17
Missing Authorization and Authentication for Critical Functions
Lecture1.18
Session Fixation
Lecture1.19
Weak Data Encryption
Lecture1.20
Information Leakage
Package Details for Students 0/15
Package Details includes the benefits of attending this course at Craw Security,India
Lecture2.1
Official Training by certified instructors
Lecture2.2
Head-2-Head training by Certified Subject matter experts
Lecture2.3
Highly interactive lectures, group exercises, and review sessions
Lecture2.4
Intensive Hands-on Training
Lecture2.5
2 years membership of bytecode international training group
Lecture2.6
Chance to become country representative
Lecture2.7
Certification Exam Fees Included.
Lecture2.8
Individual study environment
Lecture2.9
Training Environment
Lecture2.10
Practical live hacking
Lecture2.11
Concept based training
Lecture2.12
24/7 High speed internet connectivity
Lecture2.13
Limited candidates in class
Lecture2.14
Stay, food( breakfast, lunch and dinner)
Lecture2.15
Post training support after training & certification
BUY THIS COURSE
Rs. 15000.00
Contact Us- 9599662445 Phone- 01140394315
Email- info@craw.in
Visit Us on- www.craw.in
Address-
First Floor, Plot no. 4, Lane no. 2, Kehar Singh Estate, Saket metro station, Saidulajab, New Delhi 110030

Very informative blog. I found lot of information on mobile application security and IAST vendors. Thanks for sharing useful information.
ReplyDelete