OWASP TOP 10 Based
Training Course *
Bonsai’s OWASP Top 10 Based Training Course focuses on the most risky Web vulnerabilities that can be found in the wild. During this one-day course you are going to attend a series of lectures followed by some hands-on practices and demonstrations. On each practice you will identify vulnerabilities and challenge your understanding on exploiting said vulnerabilities.
This course was developed so that participants with various levels of knowledge can benefit from it as much as possible.
Our training experience helped us create the best OWASP Top 10 Based Training Course, which is oriented in PCI Standard for Payment Applications.
Bonsai’s OWASP TOP 10 Based Training Course was specially designed to meet the essential security needs of Web application developers, QA testers and computer information security experts.
Objectives
Provide the attendees with the knowledge, tools, resources and necessary techniques to understand the different types of Web vulnerabilities in the OWASP Top 10.
Understand the vulnerabilities in a theoretical and practical aspect to be able to identify and fully understand them.
Apply the tools and techniques used by the professionals in a controlled environment with a hands-on methodology an live demonstrations.
Course contents
- OWASP Top 10
- Introduction
- Risk management
- PCI Security Council & OWASP
- Basics for safe Web Application development
- Tainted variables
- Sensitive sinks
- Validation functions
- A1 - Injection
- Interpreters
- OS Commanding
- SQL Injection
- Login Bypass
- Blind SQL Injection
- SQL Injection Countermeasures
- LDAP Injection
- XPath / JSON Injection
- A2 - Cross-site Scripting (XSS)
- Reflexive and persistent
- Advanced techniques
- A3 - Broken authentication and session management
- Cookies
- Attacking session
- Session Fixation
- Session Prediction
- A4 - Insecure direct object reference
- Authorization control in objects
- Path Traversal
- Null byte
- A5 - Cross-site Request Forgery (XSRF)
- A6 - Security Misconfiguration
- Backup files
- Local databases
- Hidden HTML fields
- Directory Enumeration
- Directory Indexing
- A7 - Insecure Cryptographic Storage
- A8 - Failure to Restrict URL Access
- A9 - Insufficient Transport Layer Protection
- Digital Certificates
- HTTPS Protocol
- A10 - Unvalidated Redirects and Forwards
Deliverables
The training deliverables include:
- Booklet with training course slides
- Live CD with the Web Application Security tools used during the training
- VMware image with the training environment
- Certificate of completion
- OWASP Top 10 Cheat-sheet
Trainer
The training will be delivered by Nahuel Grisolía, an expert in the Web Application Security field, with more than four years of on the field and research experience with the support of Andrés Riancho, Bonsai Information Security founder..
Additional information
The training is going to be delivered on April 15 (9:00 to 18:00) in Av. Rivadavia 413 - 4th floor, Capital Federal.
The payment methods available are: Cash, Bank transfer, Paycheck y Dinero Mail.
$1.100 ARS + TAX. Reserve your place !
Reserve your place ! 15% Discount before March, 21st
Get group discounts !
* This is an unofficial training course
If you have any other questions, contact us.
Train your developers with us, and we’ll give you back your weekends!
Get a Quotation for the best OWASP TOP 10 Based Training Course.

English
Español