EWASEC-PY - Extended Web application security in Python - Online Training - English - Webinar von Fast Lane Institute for Knowledge Transfer

Inhalte

Day 1
  • Cyber security basics
    • What is security?
    • Threat and risk
    • Cyber security threat types – the CIA triad
    • Consequences of insecure software
  • The OWASP Top Ten 2021
    • The OWASP Top 10 2021
    • A01 - Broken Access Control
      • Access control basics
      • Failure to restrict URL access
      • Confused deputy
      • File upload
      • Cross-site Request Forgery (CSRF)
    • A02 - Cryptographic Failures
      • Information exposure
      • Cryptography for developers
    Day 2
    • A03 - Injection
      • Input validation
      • Injection
      • SQL injection
      • Parameter manipulation
      • Code injection
      • HTML injection - Cross-site scripting (XSS)
    Day 3
    • A04 - Insecure Design
      • The STRIDE model of threats
      • Secure design principles of Saltzer and Schroeder
      • Client-side security
    • A05 - Security Misconfiguration
      • Configuration principles
      • Server misconfiguration
      • Python configuration best practices
      • Cookie security
      • XML entities
    • A06 - Vulnerable and Outdated Components
      • Using vulnerable components
      • Assessing the environment
      • Hardening
      • Untrusted functionality import
      • Malicious packages in Python
      • Vulnerability management
    Day 4
    • A07 - Identification and Authentication Failures
      • Authentication
      • Session management
      • Password management
    • A08 - Software and Data Integrity Failures
      • Integrity protection
      • Subresource integrity
    • A09 - Security Logging and Monitoring Failures
      • Logging and monitoring principles
      • Insufficient logging
      • Case study – Plaintext passwords at Facebook
      • Logging best practices
      • Monitoring best practices
    • A10 - Server-side Request Forgery (SSRF)
      • Server-side Request Forgery (SSRF)
      • Case study – SSRF and the Capital One breach
    • Web application security beyond the Top Ten
      • Denial of service
    • Wrap up
      • Secure coding principles
      • And now what?
Day 1
  • Cyber security basics
    • What is security?
    • Threat and risk
    • Cyber security threat types – the CIA triad
    • Consequences of insecure software
  • The OWASP Top Ten 2021
    • The OWASP Top 10 2021
    • A01 - Broken Access Co ...
Mehr Informationen >>

Lernziele

  • Getting familiar with essential cyber security concepts
  • Understanding how cryptography supports security
  • Learning how to use cryptographic APIs correctly in Python
  • Understanding Web application security issues
  • Detailed analysis of the OWASP Top Ten elements
  • Putting Web application security in the context of Python
  • Going beyond the low hanging fruits
  • Input validation approaches and principles
  • Managing vulnerabilities in third party components
  • Getting familiar with essential cyber security concepts
  • Understanding how cryptography supports security
  • Learning how to use cryptographic APIs correctly in Python
  • Understanding Web application security ...
Mehr Informationen >>

Zielgruppen

Python developers working on Web applications.

Termine und Orte

Datum Uhrzeit Dauer Preis
Webinar
10.06.2024 - 13.06.2024 10:00 - 17:30 Uhr 30 h Mehr Informationen >  
12.08.2024 - 15.08.2024 10:00 - 17:30 Uhr 30 h Mehr Informationen >  

SG-Seminar-Nr.: 6989101

Preis jetzt anfragen

Seminar merken ›

Semigator berücksichtigt

  • Frühbucher-Preise
  • Last-Minute-Preise
  • Gruppenkonditionen

und verfügt über Sonderkonditionen mit einigen Anbietern.

Der Anbieter ist für den Inhalt verantwortlich.

Veranstaltungsinformation

  • Webinar
  • Englisch
    • Teilnahmebestätigung
  • 30 h

Ihre Vorteile mehr erfahren

  • Anbietervergleich von über 1.500 Seminaranbietern
  • Vollständige Veranstaltungsinformationen
  • Schnellbuchung
  • Persönlicher Service
Datum Uhrzeit Dauer Preis
Webinar
10.06.2024 - 13.06.2024 10:00 - 17:30 Uhr 30 h Mehr Informationen >  
12.08.2024 - 15.08.2024 10:00 - 17:30 Uhr 30 h Mehr Informationen >