CONTACT US

Red Team

WEB APPLICATION PENETRATION TEST

With this training, participants will understand how web applications work, their vulnerabilities and solutions to these vulnerabilities.

Who Should Participate?

IT Security Officers, Auditors, Security Professionals, Website Administrators, Web Application Developers, Information Security Professionals, System Professionals, Network Professionals, Forensic IT Professionals, Law Enforcement

Program

•    HTTP Security Headers 
•    Transport Layer Security (TLS, SSL) 
•    Secure TLS Configuration 
•    HTTP Authentication 
 

•    Test Steps 
•    General Information on Types of Vulnerabilities in Web Applications 
•    Passive Information Collection Steps 
•    Active Information Gathering Steps 
•    Mapping the Web Application 
•    Browser Plugins Used for Web Application Security Testing 
•    Web Proxy (Burp, Zap, Fiddler, Charles) 
•    Automatized Tools 
•    Web Cache Deception 
•    Request Smuggling 
•    Server Side Template Injection
 

•    A1-Injection 
•    A2-Broken Authentication 
•    A3-Sensitive Data Exposure 
•    A4-Xml External Entities (Xxe) 
•    A5-Broken Access Control 
•    A6-Security Misconfigurations 
•    A7-Cross Site Scripting (Xss) 
•    A8-Insecure Deserialization 
•    A9-Using Components With Known Vulnerabilities 
•    A10-Insufficient Logging And Monitoring  

 

 

TRAINING DETAILS
QUOTA
Last 2 places
DATE
DURATION
5 Days
LEVEL
LANGUAGE
TYPE OF TRAINING
Online and Classroom
CERTIFICATE

FEATURED TRAININGS

Plan and implement the trainings you desire for your organization!

You can plan the trainings you need at different durations and with content that is specific to your institution. Please contact us for detailed content and planning.

GET INFORMATION

Eğitim Formu


Add an ally to your defense

Add an ally to your defense


Experience first-hand how ADEO's 24x7 end-to-end security approach can help you achieve better results. Enhance your security coverage with our team of security experts, who work as an extension of your team, and reduce your risks with their rapid response capabilities. Maximize the value of your current security products by incorporating operational functionality into your telemetry data.

Reduce your average remediation time with our automation, playbooks, and incident response expertise. Take control of all your security alerts by managing, prioritizing, and viewing them from a single dashboard across your entire security infrastructure.