Hands-on Attack & Defense
In this fully packed hands-on bootcamp-style training, we will experience how hackers approach a typical web application to learn about the security vulnerabilities seen in many web applications and backends/APIs.
Also, we often switch the sides during the training into the defender’s perspective to learn how primary and secondary countermeasures harden the security posture of today’s applications and backends in a defense-in-depth way.
All exercises are executed against an attendee-individual training environment, which I prepare and individually spawn for each attendee in my cloud.
My hands-on web security bootcamp covers many vulnerabilities and defense measures, including:
- Injection Vulnerabilities, including Post-Exploitation towards Remote Code Execution (RCE)
- XML External Entity Attacks (XXE)
- Path-Traversals (including ClassPath-Traversals)
- Cross-Site Scripting (XSS): Reflected, Persistent, DOM-based and different contexts
- Session Attacks, etc.
- Authentication Bypass
- Information Disclosures
- Server-Side Request Forgery (SSRF), especially in cloud-based environments
- Attacks on File-Uploads and -Downloads
- Attacks on WebSockets
- Java Deserialization Vulnerabilities & Attacks
- Advanced XML Attacks (leading to RCEs)
- JSON Attacks (leading to RCEs)
- and many more
This bootcamp-style training introduces the mentioned vulnerabilities and focuses also on defensive aspects to remediate these vulnerabilities in a defense-in-depth style. If instead you’re more offensive-oriented and interested in the art of exploitation of these vulnerabilities rather than the defensive approaches, the Pentesting Training might be of more interest to you.
Being a full-fledged bootcamp training, also DevSecOps scan automation techniques are presented. If you’re interested in automation of security scans inside CI/CD build pipelines, the DevSecOps Coaching might also be of more interest to you, either as an addition or a replacement.
What attendees will receive
All my trainings can be held in German (native speaker) or English (business fluent).
Attendees receive the following along with my training:
- Access to cloud-based training environments (individually spawned for each attendee).
- All slides and workshop material as a set of PDFs.
- Lifetime access to GitHub and DockerHub repos with my training environments in order to recap all exercises with a working setup (including freshly added stuff in the future).
- Support via mail for setup and exercise handling afterwards.
- Printed and signed Certificate of Attendance listing the training contents.
As always in life, there is no one-fits-all solution. So regarding the concrete setup and execution of my trainings and workshops, you have different options and variants to choose from.
Fully customizable training agenda
In case you want certain aspects of your technology stack or specific internal process or tools covered during the training: Let’s talk
The training agenda can be customized to your needs, resulting in an individual setup and content.
On-site or Remote? – Choice is yours!
My trainings and workshops can be executed on-site (either directly at your office or at one of my training sites) as well as fully remote for home-office workers. Even hybrid variants are possible, where some remote-only workers can join online, while I execute the training on-site for the majority of the attendees.
I’ve already conducted numerous online-based variants of my trainings, even for bigger audience groups. In case you prefer an online-based variant, I can either use your corporate conferencing system to make it as seamless as possible for the attendees. Or you can access the conferencing solution that I prefer (after having tested many I’ve a nice excellent working solution ready) including live-editing of shared whiteboards for workshop exercises.
Either way, attendees just need a browser as nothing needs to be installed locally, since my training runs with attendee-individual environments in my cloud.
Alternative option: Professional training recording
In case you would like to have a customized version for your company recorded as a set of chapters and lessons for your in-house video-based electronic learning platform: Let’s talk
I can record a customized training session (without attendees) and provide you with professionally cut chapters exported as SCORM, MPEG, and other formats. This package includes digital training slides and the runnable training environment for local offline training. If you and all attendees prefer to record a live training while being held, this is also possible and would produce a video handout of the full course for recapping material afterwards.
That way several companies have successfully enriched their own internal video-based training offers with my hands-on security workshops imported into their own electronic learning platforms.