Course : Web application security, overview

Seminar - 2d - 14h00 - Ref. SEW
Price : 1850 € E.T.

Web application security, overview




This seminar provides an overview of Web threats. It details vulnerabilities in browsers, social networks, SSL/TLS and X509 certificates, as well as Java EE, .NET and PHP applications. It presents solutions for protecting and controlling application security.


INTER
IN-HOUSE
CUSTOM

Seminar in person or remote class
Disponible en anglais, à la demande

Ref. SEW
  2d - 14h00
1850 € E.T.




This seminar provides an overview of Web threats. It details vulnerabilities in browsers, social networks, SSL/TLS and X509 certificates, as well as Java EE, .NET and PHP applications. It presents solutions for protecting and controlling application security.


Teaching objectives
At the end of the training, the participant will be able to:
Identify security threats to Web applications
Web security protocols
Understanding attack typologies
Securing Web applications

Intended audience
CIOs, CISOs, security managers, developers, designers, project managers integrating security constraints, network, IT and system managers or administrators.

Prerequisites
Basic computer and network skills.

Course schedule

1
Web application threats and vulnerabilities

  • Major Web application risks according to IBM X-Force and OWASP.
  • Cross Site Scripting (XSS), injection and session-based attacks.
  • Fault propagation with a Web Worm.
  • Attacks on standard configurations.

2
SSL and TLS security protocols

  • SSL v2/v3 and TLS, PKI, X509 certificates, certification authority.
  • SSL's impact on UTM and IDS/IPS firewall security.
  • SSL/TLS vulnerabilities and attacks. Techniques for capturing and analyzing SSL flows.
  • HTTPS stripping attack on secure links.
  • Attacks on X509 certificates, OCSP protocol.
  • SSL and Web application performance.

3
User- and browser-targeted attacks

  • Attacks on Web browsers, Rootkit.
  • Smartphone security for surfing the Net.
  • Malicious code and social networks.
  • Social Engineering techniques.

4
Targeted attacks on authentication

  • Authentication via HTTP, SSL with client X509 certificate.
  • Implement strong software-based authentication.
  • Non-intrusive (agentless) Web SSO solution.
  • Main attacks on authentication.

5
Web services security

  • Protocols, security standards XML Encryption, XML Signature, WS-Security/Reliability.
  • Injection (XML injection...), brute force or replay attacks.
  • Application firewalls for Web Services.
  • Main players and products on the market.

6
Efficiently securing Web applications

  • Hardening: securing the system and HTTP server.
  • Virtualization and security for Web applications.
  • .NET, PHP and Java environments. The 5 SDL phases.
  • Fuzzing techniques. Qualify your application with ASVS.
  • WAF: what efficiency, what performance?

7
Controlling Web application security

  • Pentest, security audit, vulnerability scanners.
  • Organize an effective technology watch.
  • Reporting security incidents.
Demonstration
Implementation of a Web server with X509 EV certificate: analysis of protocol exchanges. Exploitation of a critical security flaw on the HTTP front-end. HTTPS Stripping attack.


Publication date : 07/24/2024



This programme is an original creation, developed by the teaching teams at ORSYS Formation. Any reproduction, representation, adaptation or use, in whole or in part, without the prior written authorisation of ORSYS, is strictly prohibited. ORSYS reserves the right to take any action necessary to protect its intellectual property rights.

Dates and locations
Select your location or opt for the remote class then choose your date.
Remote class

Dernières places
Date garantie en présentiel ou à distance
Session garantie

REMOTE CLASS
2026 : 8 Sep., 26 Nov.

2027 : 23 Nov., 23 Nov.

PARIS LA DÉFENSE
2026 : 8 Sep., 26 Nov.



This programme is an original creation, developed by the teaching teams at ORSYS Formation. Any reproduction, representation, adaptation or use, in whole or in part, without the prior written authorisation of ORSYS, is strictly prohibited. ORSYS reserves the right to take any action necessary to protect its intellectual property rights.