SlideShare a Scribd company logo
Web Application Security
      Course Overview




               Satish.B
               Email:
               satishb3@securitylearn.net
Course Content

History of web application
    Introduction to web application architecture

Uniform Resource Locator (URL)

HTTP
        Introduction
        HTTP Methods
        WEBDAV methods
        Request/Response analysis
        Security problems with http

HTTPS
        Handshake protocol
        Record protocol

Proxy
        Man in the middle attack
        Tools: Burp proxy, Paros proxy, web scarab

Encoding Techniques
      URL Encoding
      HTML Encoding
      Unicode Encoding
      Tools: Burp decoder

Profiling Application
        Spiders, crawlers
        Search engine discovery
        Banner Grabbing
        Robots.txt
        Analysis of error codes
        Tools: HttpPrint, netcraft

Attacking Authentication
       Authentication Types
       Brute force attacks
       Analyzing Auto complete options
       Insecure credential transmission
       Session puzzle attacks
       Authentication bypass techniques
       Shoulder surfing

 2                                                   http://www.securitylearn.net
CAPTCHA Rebinding attacks
       Countermeasures
       Tools: Bruter, Burp Repeater, Burp Intruder

Attacking Authorization
       Authorization types
       Parameter tampering
       Horizontal privilege escalation
       Vertical privilege escalation
       Referrer spoofing

Cryptography weakness
      Symmetric cryptography
      Asymmetric cryptography
      Substitution cipher
      Stream cipher
      Block cipher
      Steganography
      SSL cipher testing
      Cracking hashes
      Padding oracle attack
      Cracking ECB encryption
      Tools: SSLDigger, MD5 crack

Attacking Session management
       Introduction
       Secure flag
       HTTPOnly flag
       Cookie Domain & Path
       Session Token analysis
       Session fixation
       Cookie transmission mechanisms
       Tools: Burp sequencer
       Timeout issues

Cross site scripting attacks
       Same origin policy
       Reflective XSS
       Stored XSS
       DOM based XSS
       Anatomy of XSS
       Exploitation
       Impact of XSS
       XSS Shell

 3                                                   http://www.securitylearn.net
XSS & Metasploit
       Black list/White list
       Input validation
       Output encoding
       Remediation
       Tools: Beef

SQL injection
       Error based SQLi
       Blind SQLi
       SQLi exploitation
       Data extraction with UNION queries
       Data extraction with inference techniques
       Command execution with SQLi
       Impact of SQLi
       Remediation
       Stored procedures Vs Parameterized queries
       Tools: SQLMap, Absinthe

Cross site request forgery
       Anatomy of CSRF
       Remediation
       CAPTCHA Rebinding attack
       Tool: CSRFTester

URL Redirection attacks
      Phishing attacks
      Remediation

HTTP Response splitting
      Cache positioning
      Command execution

Input validation attacks
       File Uploads
       Path traversal attacks
       Local file inclusions
       Remote file inclusions
       Command Execution
       Remediation Techniques

Server Configuration issues
       WEBDAV methods
       Caching vulnerabilities
       Directory listing

 4                                                  http://www.securitylearn.net
Attacking Web Server
       Denial of service attacks
       Buffer over flows
       Remediation

OWASP Top10 web application risks

Scanners
      Usage of tools
      Pros, Cons & Problems with scanners
      IBM- AppScan
      HP- WebInspect

Risk Assessment
       OWASP Risk Rating methodology

Pentest Reports
      Executive reports
      Detailed reports

Web Application Security Checklist



Contact
Satish B
Email: satishb3@securitylearn.net
       satishb3@hotmail.com




 5                                          http://www.securitylearn.net

More Related Content

What's hot (20)

PDF
Session3 data-validation-sql injection
zakieh alizadeh
 
PDF
S5-Authorization
zakieh alizadeh
 
PPT
Cross Site Request Forgery Vulnerabilities
Marco Morana
 
PPTX
3. backup file artifacts - mazin ahmed
Rashid Khatmey
 
PPTX
A8 cross site request forgery (csrf) it 6873 presentation
Albena Asenova-Belal
 
PDF
Cross-Site Request Forgery Vulnerability: “A Sleeping Giant”
Capgemini
 
PDF
Session1-Introduce Http-HTTP Security headers
zakieh alizadeh
 
PPTX
121 desarrollando aplicaciones-seguras_con_gene_xus
GeneXus
 
PPT
Cross Site Request Forgery
Tony Bibbs
 
PDF
Session10-PHP Misconfiguration
zakieh alizadeh
 
PDF
Web application sec_3
vhimsikal
 
PPTX
Understanding Cross-site Request Forgery
Daniel Miessler
 
PPTX
SSRF exploit the trust relationship
n|u - The Open Security Community
 
PDF
Session2-Application Threat Modeling
zakieh alizadeh
 
PPT
Web 2.0 Hacking
blake101
 
PDF
Grey H@t - Cross-site Request Forgery
Christopher Grayson
 
PPTX
Introduction to CSRF Attacks & Defense
Surya Subhash
 
PPTX
Owasp security testing methodlogies –part2
robin_bene
 
PPTX
Deep understanding on Cross-Site Scripting and SQL Injection
Vishal Kumar
 
Session3 data-validation-sql injection
zakieh alizadeh
 
S5-Authorization
zakieh alizadeh
 
Cross Site Request Forgery Vulnerabilities
Marco Morana
 
3. backup file artifacts - mazin ahmed
Rashid Khatmey
 
A8 cross site request forgery (csrf) it 6873 presentation
Albena Asenova-Belal
 
Cross-Site Request Forgery Vulnerability: “A Sleeping Giant”
Capgemini
 
Session1-Introduce Http-HTTP Security headers
zakieh alizadeh
 
121 desarrollando aplicaciones-seguras_con_gene_xus
GeneXus
 
Cross Site Request Forgery
Tony Bibbs
 
Session10-PHP Misconfiguration
zakieh alizadeh
 
Web application sec_3
vhimsikal
 
Understanding Cross-site Request Forgery
Daniel Miessler
 
SSRF exploit the trust relationship
n|u - The Open Security Community
 
Session2-Application Threat Modeling
zakieh alizadeh
 
Web 2.0 Hacking
blake101
 
Grey H@t - Cross-site Request Forgery
Christopher Grayson
 
Introduction to CSRF Attacks & Defense
Surya Subhash
 
Owasp security testing methodlogies –part2
robin_bene
 
Deep understanding on Cross-Site Scripting and SQL Injection
Vishal Kumar
 

Similar to Web application security - Course overview (20)

PDF
Romulus OWASP
Grupo Gesfor I+D+i
 
PPT
Pentesting web applications
Satish b
 
PPT
AppSec 2007 - .NET Web Services Hacking
Shreeraj Shah
 
PPT
Intro to Web Application Security
Rob Ragan
 
PPTX
What's new in​ CEHv11?
EC-Council
 
PDF
wapt lab 6 - converted (2).pdfwaptLab09 tis lab is used for college lab exam
imgautam076
 
PPT
Assessment methodology and approach
Blueinfy Solutions
 
DOCX
Ceh certified ethical hacker
bestip
 
ODP
OWASP Secure Coding
bilcorry
 
PPT
Hacking web applications
phanleson
 
PDF
Fraud detection system
baladutt
 
PPT
Owasp Top 10 And Security Flaw Root Causes
Marco Morana
 
PPT
Secure SDLC for Software
Shreeraj Shah
 
PPT
Hack applications
enrizmoore
 
PDF
Cyber Crime / Cyber Secuity Testing Architecture by MRITYUNJAYA HIKKALGUTTI (...
MrityunjayaHikkalgut1
 
PPTX
Secure RESTful API Automation With JavaScript
Jonathan LeBlanc
 
PPTX
Altitude SF 2017: Security at the edge
Fastly
 
PPTX
04. xss and encoding
Eoin Keary
 
PPTX
Waf bypassing Techniques
Avinash Thapa
 
Romulus OWASP
Grupo Gesfor I+D+i
 
Pentesting web applications
Satish b
 
AppSec 2007 - .NET Web Services Hacking
Shreeraj Shah
 
Intro to Web Application Security
Rob Ragan
 
What's new in​ CEHv11?
EC-Council
 
wapt lab 6 - converted (2).pdfwaptLab09 tis lab is used for college lab exam
imgautam076
 
Assessment methodology and approach
Blueinfy Solutions
 
Ceh certified ethical hacker
bestip
 
OWASP Secure Coding
bilcorry
 
Hacking web applications
phanleson
 
Fraud detection system
baladutt
 
Owasp Top 10 And Security Flaw Root Causes
Marco Morana
 
Secure SDLC for Software
Shreeraj Shah
 
Hack applications
enrizmoore
 
Cyber Crime / Cyber Secuity Testing Architecture by MRITYUNJAYA HIKKALGUTTI (...
MrityunjayaHikkalgut1
 
Secure RESTful API Automation With JavaScript
Jonathan LeBlanc
 
Altitude SF 2017: Security at the edge
Fastly
 
04. xss and encoding
Eoin Keary
 
Waf bypassing Techniques
Avinash Thapa
 
Ad

More from Satish b (6)

PPTX
Hacking and securing ios applications
Satish b
 
PDF
Forensic analysis of iPhone backups (iOS 5)
Satish b
 
PDF
iPhone forensics course overview
Satish b
 
PPT
iPhone forensics on iOS5
Satish b
 
PPTX
Pentesting iPhone applications
Satish b
 
PPT
padding oracle attack
Satish b
 
Hacking and securing ios applications
Satish b
 
Forensic analysis of iPhone backups (iOS 5)
Satish b
 
iPhone forensics course overview
Satish b
 
iPhone forensics on iOS5
Satish b
 
Pentesting iPhone applications
Satish b
 
padding oracle attack
Satish b
 
Ad

Recently uploaded (20)

PDF
Public Health For The 21st Century 1st Edition Judy Orme Jane Powell
trjnesjnqg7801
 
PDF
DIGESTION OF CARBOHYDRATES ,PROTEINS AND LIPIDS
raviralanaresh2
 
PPTX
Peer Teaching Observations During School Internship
AjayaMohanty7
 
PPTX
Tanja Vujicic - PISA for Schools contact Info
EduSkills OECD
 
PDF
Romanticism in Love and Sacrifice An Analysis of Oscar Wilde’s The Nightingal...
KaryanaTantri21
 
PDF
Supply Chain Security A Comprehensive Approach 1st Edition Arthur G. Arway
rxgnika452
 
PPT
M&A5 Q1 1 differentiate evolving early Philippine conventional and contempora...
ErlizaRosete
 
PPTX
SYMPATHOMIMETICS[ADRENERGIC AGONISTS] pptx
saip95568
 
PPTX
Urban Hierarchy and Service Provisions.pptx
Islamic University of Bangladesh
 
PPTX
Elo the Hero is an story about a young boy who became hero.
TeacherEmily1
 
PPTX
Elo the HeroTHIS IS A STORY ABOUT A BOY WHO SAVED A LITTLE GOAT .pptx
JoyIPanos
 
PDF
CAD25 Gbadago and Fafa Presentation Revised-Aston Business School, UK.pdf
Kweku Zurek
 
PDF
Our Guide to the July 2025 USPS® Rate Change
Postal Advocate Inc.
 
PDF
Rapid Mathematics Assessment Score sheet for all Grade levels
DessaCletSantos
 
DOCX
ANNOTATION on objective 10 on pmes 2022-2025
joviejanesegundo1
 
PDF
Learning Styles Inventory for Senior High School Students
Thelma Villaflores
 
DOCX
DLL english grade five goof for one week
FlordelynGonzales1
 
PPTX
Martyrs of Ireland - who kept the faith of St. Patrick.pptx
Martin M Flynn
 
PPTX
JSON, XML and Data Science introduction.pptx
Ramakrishna Reddy Bijjam
 
PPTX
Photo chemistry Power Point Presentation
mprpgcwa2024
 
Public Health For The 21st Century 1st Edition Judy Orme Jane Powell
trjnesjnqg7801
 
DIGESTION OF CARBOHYDRATES ,PROTEINS AND LIPIDS
raviralanaresh2
 
Peer Teaching Observations During School Internship
AjayaMohanty7
 
Tanja Vujicic - PISA for Schools contact Info
EduSkills OECD
 
Romanticism in Love and Sacrifice An Analysis of Oscar Wilde’s The Nightingal...
KaryanaTantri21
 
Supply Chain Security A Comprehensive Approach 1st Edition Arthur G. Arway
rxgnika452
 
M&A5 Q1 1 differentiate evolving early Philippine conventional and contempora...
ErlizaRosete
 
SYMPATHOMIMETICS[ADRENERGIC AGONISTS] pptx
saip95568
 
Urban Hierarchy and Service Provisions.pptx
Islamic University of Bangladesh
 
Elo the Hero is an story about a young boy who became hero.
TeacherEmily1
 
Elo the HeroTHIS IS A STORY ABOUT A BOY WHO SAVED A LITTLE GOAT .pptx
JoyIPanos
 
CAD25 Gbadago and Fafa Presentation Revised-Aston Business School, UK.pdf
Kweku Zurek
 
Our Guide to the July 2025 USPS® Rate Change
Postal Advocate Inc.
 
Rapid Mathematics Assessment Score sheet for all Grade levels
DessaCletSantos
 
ANNOTATION on objective 10 on pmes 2022-2025
joviejanesegundo1
 
Learning Styles Inventory for Senior High School Students
Thelma Villaflores
 
DLL english grade five goof for one week
FlordelynGonzales1
 
Martyrs of Ireland - who kept the faith of St. Patrick.pptx
Martin M Flynn
 
JSON, XML and Data Science introduction.pptx
Ramakrishna Reddy Bijjam
 
Photo chemistry Power Point Presentation
mprpgcwa2024
 

Web application security - Course overview

  • 1. Web Application Security Course Overview Satish.B Email: [email protected]
  • 2. Course Content History of web application Introduction to web application architecture Uniform Resource Locator (URL) HTTP Introduction HTTP Methods WEBDAV methods Request/Response analysis Security problems with http HTTPS Handshake protocol Record protocol Proxy Man in the middle attack Tools: Burp proxy, Paros proxy, web scarab Encoding Techniques URL Encoding HTML Encoding Unicode Encoding Tools: Burp decoder Profiling Application Spiders, crawlers Search engine discovery Banner Grabbing Robots.txt Analysis of error codes Tools: HttpPrint, netcraft Attacking Authentication Authentication Types Brute force attacks Analyzing Auto complete options Insecure credential transmission Session puzzle attacks Authentication bypass techniques Shoulder surfing 2 http://www.securitylearn.net
  • 3. CAPTCHA Rebinding attacks Countermeasures Tools: Bruter, Burp Repeater, Burp Intruder Attacking Authorization Authorization types Parameter tampering Horizontal privilege escalation Vertical privilege escalation Referrer spoofing Cryptography weakness Symmetric cryptography Asymmetric cryptography Substitution cipher Stream cipher Block cipher Steganography SSL cipher testing Cracking hashes Padding oracle attack Cracking ECB encryption Tools: SSLDigger, MD5 crack Attacking Session management Introduction Secure flag HTTPOnly flag Cookie Domain & Path Session Token analysis Session fixation Cookie transmission mechanisms Tools: Burp sequencer Timeout issues Cross site scripting attacks Same origin policy Reflective XSS Stored XSS DOM based XSS Anatomy of XSS Exploitation Impact of XSS XSS Shell 3 http://www.securitylearn.net
  • 4. XSS & Metasploit Black list/White list Input validation Output encoding Remediation Tools: Beef SQL injection Error based SQLi Blind SQLi SQLi exploitation Data extraction with UNION queries Data extraction with inference techniques Command execution with SQLi Impact of SQLi Remediation Stored procedures Vs Parameterized queries Tools: SQLMap, Absinthe Cross site request forgery Anatomy of CSRF Remediation CAPTCHA Rebinding attack Tool: CSRFTester URL Redirection attacks Phishing attacks Remediation HTTP Response splitting Cache positioning Command execution Input validation attacks File Uploads Path traversal attacks Local file inclusions Remote file inclusions Command Execution Remediation Techniques Server Configuration issues WEBDAV methods Caching vulnerabilities Directory listing 4 http://www.securitylearn.net
  • 5. Attacking Web Server Denial of service attacks Buffer over flows Remediation OWASP Top10 web application risks Scanners Usage of tools Pros, Cons & Problems with scanners IBM- AppScan HP- WebInspect Risk Assessment OWASP Risk Rating methodology Pentest Reports Executive reports Detailed reports Web Application Security Checklist Contact Satish B Email: [email protected] [email protected] 5 http://www.securitylearn.net