Publication date : 02/29/2024

Course : Web application security, advanced

Practical course - 3d - 21h00 - Ref. SEI
Price : 2100 € E.T.

Web application security, advanced




This advanced course will enable you to enhance your skills in protecting yourself and reacting more effectively to the many threats posed by the Web. You'll learn how to audit the security of your applications, test them and implement the most appropriate countermeasures.


INTER
IN-HOUSE
CUSTOM

Practical course in person or remote class
Disponible en anglais, à la demande

Ref. SEI
  3d - 21h00
2100 € E.T.




This advanced course will enable you to enhance your skills in protecting yourself and reacting more effectively to the many threats posed by the Web. You'll learn how to audit the security of your applications, test them and implement the most appropriate countermeasures.


Teaching objectives
At the end of the training, the participant will be able to:
Learn how to set up an audit of a Web application
Set up a Web server with vulnerabilities to observe its behavior
Implement security measures for Web applications
Implementing a private certification authority with certificate integration in an application
Use a web spider to detect broken links and pages with or without authentication

Intended audience
Network and systems administrators, webmasters.

Prerequisites
Good knowledge of systems and networks, basic knowledge of development or knowledge equivalent to that provided by the course "Web application security" ref. SER.

Practical details
Exercise
Numerous exercises and case studies will be proposed throughout the course.
Teaching methods
Theoretical foundations illustrated by practical exercises.

Course schedule

1
Reminder of the main security vulnerabilities

  • Cross-Site Scripting (XSS) attack.
  • Command injection and SQL injection.
  • Denial of Service (DoS) attacks.
  • Distributed Denial of Service (DDoS).
  • Buffer overflow.
  • The Open Web Application Security Project (OWASP).
Hands-on work
Set up a Web server with vulnerabilities to observe its behavior. Demonstrate how to exploit a buffer overflow.

2
Application security

  • Basic concept and importance.
  • The accounts created to run the tests.
  • Can we do without fictitious files?
  • Are test and development sequences still present in production?

3
Auditing and securing a Web application

  • Audit approach and implementation. Managing database interaction.
  • Implementing secure authentication. Exploiting an authentication flaw.
  • Error, exception and log management.
  • Analyze and correlate log information.
  • Best practices for secure forms. Example of a poorly developed form.
Hands-on work
Implementation of a three-tier infrastructure: client, Web server and databases. Simulation of an attack attempt. Analysis and solution.

4
Encryption

  • A reminder of the basic principles.
  • Implement encryption in an application. Possible uses.
  • Test whether an application is properly protected by encryption.
  • Encryption applications on the market.
Hands-on work
Implementation of a private certification authority with certificate integration in an application.

5
Testing applications

  • How to test before going live.
  • Fingerprinting: identification of server characteristics (web engine, framework, applications).
  • Use a web spider to detect broken links and pages with or without authentication and encryption.
  • How to measure application availability with a simulation.
Hands-on work
Example of attempted attacks and fingerprinting. How to write a web spider to detect broken links. Checking page authentication.


Customer reviews
4,6 / 5
Customer reviews are based on end-of-course evaluations. The score is calculated from all evaluations within the past year. Only reviews with a textual comment are displayed.
FLORENT H.
22/10/25
5 / 5

Very interesting, technically-oriented content that totally met my expectations
LUC V.
16/04/25
5 / 5

Very good trainer, able to alternate practice, theory and anecdotes.



Dates and locations
Select your location or opt for the remote class then choose your date.
Remote class

Dernières places
Date garantie en présentiel ou à distance
Session garantie

REMOTE CLASS
2026 : 25 Mar., 27 May, 5 Oct., 7 Dec.

PARIS LA DÉFENSE
2026 : 25 Mar., 27 May, 5 Oct., 7 Dec.