Вы находитесь на странице: 1из 4

Web Application Security Testing

Self-Paced | 90 Days Access | ‘WASD’ Exam Attempt | Completion Cert.

Aligned with OWASP Web Application Security: Top 10 (2017) Risk & Testing Guide (v4)

Hack2Secure’s Self-Paced Online Workshop on Web Application Security Testing provides required
exposure and understanding on different Web Security Risk and Attack vectors.

Scoped around OWASP Top 10 (2017) Web Application Security Risk and Security Testing Guide (v4),
these intensive sessions provide deep-dive on required testing tips and tricks to evaluate, test and
assess Web Application Security flaws.

Key Take Away


 OWASP Web Security Testing Framework  Exploring Web Security Risk Flaws
 Web Reconnaissance: Active & Passive  Injection Attacks
 SSL/TLS Protocol: Handshake & Testing  Cross Site Scripting (XSS)
 Web Scanning, Fingerprinting & Spidering  Cross Site Request Forgery (XSRF)
 Burp Suite, Zed Attack Proxy  Broken Authentication & Authorization
 Nmap, Netcat, Recon-Ng  Web Services & API Security Testing
 Nikto, XSSer, SQLMap, W3af  Web Application Filters & Firewalls

What You Will Receive Who Should Enroll


 Access to Self-Paced Online Sessions  Software Development Team
o 90 Days Access o Testing Team, Architects, Developers
 Soft Deliverables o Consultants, Research Engineers
 WASD Cert Exam Voucher  Application Security Team/Office
o Engineers, Testers, Analyst
o 1 Attempt, 6 months Validity
o Penetration Testers, Consultants, Auditors
o Globally Proctored Exam by Pearson VUE
 Students
 Online Training Completion Certificate
o Looking to learn skills related with Web
 Email Based Technical Support Application Security Assessment/Testing
o 90 Days Support  Anyone
 Exclusive Discounts on other H2S Programs o Looking to explore Web Security Testing
Tools, Techniques & Practices

For Web Application Security Testing (WAST) Program Enrollment, visit

https://goo.gl/K9ZTcG

For more details, www.online.hack2secure.com | training@hack2secure.com


Detailed Curriculum
Aligned with OWASP Web Application Security: Top 10 (2017) Risk & Testing Guide (v4)

Module#1: Building the Base o Directory Traversal Attacks


[Concepts, Processes & Methodologies]  Accountability
 Web Application Security o About, Secure Logging Practices
o Importance, Current Approach
 Proxy Servers (Walk-through) Module#5: Session Management
o Burp Suite, Zed Attack Proxy  “Sessions” & Tracking Methods
 HTTP Protocol  Attacks on Sessions
o History, Versions, Status Codes o Fixation, Hijacking, Tampering
o Request & Response Analysis  Securing Cookies & Headers
 SSL/TLS Protocol  Testing Session Security
o Introduction, Handshake, Testing methods  Cross Site Request Forgery
 HTTPS Protocol: Best Practices o About, How it happens
 About OWASP o Myths and Defensive Measures
o Top 10 Web Application Security Risk  CSRF Tokens, Double Submitted
o Application Security Testing Framework Cookies
o Web Application Testing Guide
 Component & Scope Walk-through Module#6: Injection Attacks
 SQL Query: Primer
Module#2: Casual Leakage Points  SQL Injection (SQLi)
[Reconnaissance] o About, Root Cause, Types & Analysis
o Automated Tool: SQLMap
 DNS Protocol
o Overview, Zone Transfers, Analysis & Scan  Command Injection:
o About, Root Cause, Attack Scenarios
 Open Source Intelligence
 [Local/Remote] File Inclusion Vulnerability
 Exploring Google Search (Google Hacking)
o Keywords & Filters
o Hacking Database (GHDB) Module#7: Cross Site Scripting (XSS)
 Website Mirroring: Httrack  JavaScript: Primer
 Exploring Internet Connected Devices: Shodan  XSS
 Web Reconnaissance Tools o Overview, Types & Analysis
o TheHarvester, Recon-Ng o Automated Tool: XSSer
 HTML Injection
Module#3: Looking for Entry Point o About, Root Cause, Attack Scenarios
[Scanning, Fingerprinting & Spidering] Module#8: Web Services & APIs
 Web Scanning: NMap, Nikto
 Web Services
 Fingerprinting Web Server o About, Security Testing Requirements
 Spidering/Crawling  Explore JSON & AJAX: Usage and Features
 Web Application Fuzzing: Directory Browsing  Web Security Attacks with SOAP Queries
o Injection Attacks
Module#4: Analyzing A.A.A. Concerns  XSS in AJAX & JSON Objects
 Authentication
o About, Types, Password Policies, Schemes
Module#9: Web Application Filters and
o Cracking Weak Passwords
 Authorization
Firewalls (WAF)
o About, Access Control Types  Web Filtering: .NET & ESAPI Filtering Options
o Privilege Escalation Attack  Web Firewall
o Insecure Direct Object References o Types, Detection & Attack methods
o Directory Traversal Attacks
 For more details, www.online.hack2secure.com | training@hack2secure.com
Web Application Security Defender (WASD)
Evaluate your Web Security Testing Essential Knowledge & Skills

Globally Available | Proctored | 180 mins. | 90 MCQ | Passing Grade: 60% | Exam Language: English

Web Application Security Defender (WASD) Certificate program evaluates individual's


implementation level skills required for Web Application Security Assessment. This program
ensures candidate's awareness on Application Security Challenges, Risk, Tools, Techniques and
methodologies along with hands-on practical level knowledge and skill-sets.

WASD is based on Application Security Industry Standards and Best Practices and ensures
Knowledge and Understanding of Secure Web Application Assessment requirements. It walks
through different phases/domains of Application Security Testing and provide required practical
strategies and methodologies to evaluate Security at every level.

Benefits Attempt to WASD Exam


 Validates your practical expertise and
is included as part of
knowledge in Web Application Security Web Application Security
Assessment Testing Self-Paced Online
 Get Global Recognition and Credibility
 Ensures Real Time skills required to handle
Training Program from
Web Application Security Risk Hack2Secure
 Demonstrate knowledge of Industry
Standards and Best Practices 1 Attempt | 6 months Voucher Validity
 Ensures effective skills to measure and Delivered globally at Pearson VUE
implement Security Controls Authorized Test Centres

To Schedule WASD Exam


www.pearsonvue.com/hack2secure

For more details, visit www.hack2secure.com/wasd


www.hack2secure.com | certificate@hack2secure.com
About Hack2Secure
Hack2Secure excels in “Information Security” Domain and offers
customised IT Security programs, including Training, Services and
Solutions. Our programs are designed by industry experts and
tailored as per specific needs. We help students, professionals
and companies with knowledge, tools and guidance required to
be at forefront of a vital and rapidly changing IT industry.

InfoSec Training
Vendor Independent, Customizable, Across Domains
Hack2Secure excels in delivering intensive, immersion security
training sessions designed to master practical steps necessary
for defending systems against the dangerous security threats.
Our wide range of fully customizable training courses allow
individual to master different aspects of Information Security as
per their industry requirement and convenience.
 Delivered Training to more than 15k+ Professionals Globally
 Vendor Independent programs aligned with Industry Security Practices and Requirements
InfoSec Certification
 Globally delivered and Proctored Security Certification programs with PearsonVUE
 Vendor Independent Programs based on Industry Security Standards and Practices

End-to-End InfoSec Services


Hack2Secure offers IT Security Professional Services to provide ways to stay ahead of Security
Threats through adaptive and proactive Security methods like
 Secure Software Development Lifecycle
 Secure Application Design & Threat Modeling
 Application Security Testing
 Network/Infrastructure Risk Assessment
 Consulting
Hack2Secure featured as:

 hack2secure 25 FASTEST GROWING CYBER SECURITY


COMPANIES IN INDIA
Source: The CEO Magazine, India
+91 (80) 49 58 32 99
10 BEST SECURITY COMPANIES in INDIA: 2017
+91 (80) 49 58 33 99 Source: Silicon Review Magazine, India

EXCELLENCE IN SECURITY TRAINING


PROGRAMMES
Source: GDS Review Magazine

www.hack2secure.com | info@hack2secure.com

Вам также может понравиться