Formation en Cybersécurité: OWASP - Top 10 - Ascent Formation
Retour aux formations
Cybersécurité

OWASP - Top 10

3 jour(s)21h

Description

Training objectives : This training will allow architects and developers to understand the main Web vulnerabilities, to correct them and to prevent them. Through a series of hands-on exercises putting you at the place of a penetration tester, you will acquire knowledge about how attackers proceed to exploit each of the vulnerabilities of the OWASP Top 10. All along the course, Students will practice on several ways to cover each of the vulnerability, allowing them to discover the mistake and understand how to mitigate.

Objectifs pédagogiques

  • Understand the main Web Vulnerabilities
  • Prevent the main Web Vulnerabilities
  • Correct the main Web Vulnerabilities

Public concerné

Architects
Developers
Technical project managers

Prérequis

Introduction to application security
A basic understanding of the 10 application security risks according to OWASP
Basic knowledge of the technologies used in Web development (HTML, Javascript, SQL, etc.)

Déroulé du programme

1

OWASP Intro

  • Refreshing about HTTP Protocol
  • WEB Application architecture
  • Briefing about OWASP and the Top 10
2

Broken Access Control

  • CORS
  • Parameter Tampering
3

Identification and Authentication Failures

  • Brute-Force Attacks and Weak passwords
  • Credential Stuffing
  • SSO and MFA : security myths
4

Injection

  • SQL Injection
  • Data validation
5

Server-Side Request Forgery

  • XXE attack
  • TOCTOU (Race Condition)
  • Network Segmentation
6

Security Misconfiguration

  • Error Handling Failures
  • Environment Hardening
7

Insecure Design

  • DevOps and Security
  • Threat Modeling
  • Network Segmentation
8

Cryptographic Failures

  • Certificates and Secure Channels
  • Data Security at Rest
9

Vulnerable and Outdated Components

  • Vulnerability Assessments and tools
  • Patch Management
10

Software and Data Integrity Failures

  • Trusted Repositories
  • Case of the SolarWinds Sunburst Attack
  • Insecure Deserialization
11

Security Logging and Monitoring Failures

  • Log Storage & Format
  • Incident Handling
  • Digital Forensics

Informations

Durée

3 jour(s)

21h

Tarif

2180 € HT

HT