Course description
The Open Web Application Security Project focuses on improving the security of software .The OWASP Top 10 is a powerful awareness document for web application security and represents a broad consensus about the most critical security risks to web applications. This course discusses the updates to the Top 10 and how threats have changed.
Each LearnNowOnline training course is made up of Modules (typically an hour in length). Within each module there are Topics (typically 15-30 minutes each) and Subtopics (typically 2-5 minutes each). There is a Post Exam for each Module that must be passed with a score of 70% or higher to successfully and fully complete the course.
Prerequisites
It would be helpful to have watched the previous OWASP courses as man of the threats still exist: OWASP, Part 1: Avoiding Hacker Tricks - OWASP, Part 2: Forgery and Phishing - OWASP, Part 3: Threats and Session Security - OWASP, Part 4: Misconfiguration and Data Encryption
Meet the expert
Robert Hurlbut is a software security architect and trainer. He is a Microsoft MVP for Developer Security / Visual Studio and Development Technologies and he holds the (ISC)2 CSSLP security certification. Robert has 30 years of industry experience in secure coding, software architecture, and software development and has served as a project manager, director of software development, chief software architect, and application security champion for several companies. He speaks at user groups, national and international conferences, and provides training for many clients.
Video Runtime
85 Minutes
Time to complete
148 Minutes
Course Outline
Objectives and Overview (02:57)
History (08:47)
Process (08:04)
Finding OWASP (03:19)
XML External Entities (09:38)
XXE Demo (15:05)
XML XXE DOTNET Demo (05:42)
Insecure Deserialization (09:55)
Insecure Deserialize Demo (08:50)
Insufficient Logging and Monitoring (08:02)
The Future of OWASP (04:50)