Course Name
Course Code : SIQ50
Venue Details
Postal Code : 11001
Session Dates
Duration: 4 days (28 hours)
This course provides a comprehensive understanding of the OWASP Top 10 security risks, their impact on applications, and the best practices for mitigating them. Participants will explore real-world vulnerabilities, hands-on exploitation, and defensive measures to secure web applications against attacks. The course includes demos, practical exercises, and case studies to enhance learning.
Overview of OWASP and the importance of web security
Understanding the OWASP Top 10 framework
Common attack vectors and hacker methodologies
How attackers bypass authentication and authorization
Exploiting IDOR (Insecure Direct Object References)
Mitigation: Role-based access control (RBAC) and proper authorization checks
Understanding insecure data transmission and storage
Attacks on weak encryption protocols
Mitigation: Strong encryption (AES, TLS 1.3) and secure key management
Exploiting SQL injection, NoSQL injection, and command injection
Cross-Site Scripting (XSS) and its variations
Mitigation: Input validation, parameterized queries, escaping user input
Identifying design flaws in applications
Secure design principles and threat modeling
Mitigation: Secure development lifecycle (SDLC) best practices
Common misconfigurations in web servers, databases, and APIs
Exploiting default credentials and weak security settings
Mitigation: Hardened configurations, security headers, and automated security scans
Risks of using outdated libraries, frameworks, and plugins
Identifying known vulnerabilities (CVE databases, OWASP Dependency-Check)
Mitigation: Regular updates, patching, and software inventory management
Exploiting weak passwords, session hijacking, and MFA bypass
Session management vulnerabilities (session fixation, token theft)
Mitigation: Strong authentication mechanisms (OAuth, SSO, MFA)
Understanding insecure deserialization and supply chain attacks
Exploiting malicious package injection and dependency attacks
Mitigation: Code signing, secure CI/CD pipelines, and integrity checks
Importance of real-time monitoring and alerting
Identifying log injection attacks and log tampering
Mitigation: Centralized logging, SIEM tools, and anomaly detection
Understanding SSRF and its impact on internal services
Exploiting cloud services, metadata APIs, and internal networks
Mitigation: URL whitelisting, proper input validation, and firewall rules
Mode of Delivery : The event can be attended both online and at nearby ProgNXT classroom by Individual Professionals and Corporate Employees as per the seat availability. Please Contact Us at [email protected] for checking the seat availability
Audience : We have a global audience that logs in to using their own computers to work hand in hand with our world-class instructors.
Assessment : Each training course will have ProgNXT Assessment at the end.
Certification : After successful passing of ProgNXT Assessment, ProgNXT Certification will be provided, which has got acceptance in 55+ Countries.
| Global Region | Location | Start Date | End Date | Action |
|---|---|---|---|---|
| | | | | |
| | | | | |
| | | | | |
| | | | | |
| | | | | |