From Zero to Hero in Web Security Research - Jubilee 2
L'événement s'est terminé

From Zero to Hero in Web Security Research - Jubilee 2

Par DEF CON WORKSHOPS
Bally's Las VegasLas Vegas, NV
août 7 , 2021 at 10:00 PDT
Aperçu

Title: From Zero to Hero in Web Security Research Instructor: Roman Zaikin

Title: From Zero to Hero in Web Security Research

Instructor: Roman Zaikin, Yaara Shriki, Kila Barda, Oded Vanunu

Abstract: "Web applications play a vital role in every modern organization. If your organization does not properly test and secure its web apps, adversaries can compromise these applications, damage business functionality, and steal data. Unfortunately, many organizations operate under the mistaken impression that a web application security scanner will reliably discover flaws in their systems.

Customers expect web applications to provide significant functionality and data access. Even beyond the importance of customer-facing web applications, internal web applications increasingly represent the most commonly used business tools within any organization. Unfortunately, there is no ""patch Tuesday"" for custom web applications, so major industry studies find that web application flaws play a major role in significant breaches and intrusions.

In this workshop we will teach you how to find vulnerabilities in web security according to the latest methods and techniques. We will demonstrate every vulnerability by giving an example from vulnerability we have found in major tech companies like: Facebook, WhatsApp, Amazon, AliExpress, Snapchat, LG and more!"

Level: Beginner

Pre-Requisites:   Basic Web Concepts, Basic Web Development Skills, Ability to Understand JavaScript.

Required Materials:   Personal Laptop

Title: From Zero to Hero in Web Security Research Instructor: Roman Zaikin

Title: From Zero to Hero in Web Security Research

Instructor: Roman Zaikin, Yaara Shriki, Kila Barda, Oded Vanunu

Abstract: "Web applications play a vital role in every modern organization. If your organization does not properly test and secure its web apps, adversaries can compromise these applications, damage business functionality, and steal data. Unfortunately, many organizations operate under the mistaken impression that a web application security scanner will reliably discover flaws in their systems.

Customers expect web applications to provide significant functionality and data access. Even beyond the importance of customer-facing web applications, internal web applications increasingly represent the most commonly used business tools within any organization. Unfortunately, there is no ""patch Tuesday"" for custom web applications, so major industry studies find that web application flaws play a major role in significant breaches and intrusions.

In this workshop we will teach you how to find vulnerabilities in web security according to the latest methods and techniques. We will demonstrate every vulnerability by giving an example from vulnerability we have found in major tech companies like: Facebook, WhatsApp, Amazon, AliExpress, Snapchat, LG and more!"

Level: Beginner

Pre-Requisites:   Basic Web Concepts, Basic Web Development Skills, Ability to Understand JavaScript.

Required Materials:   Personal Laptop

Organisé par
DEF CON WORKSHOPS
Abonnés--
Événements179
Organisation8 années
Signaler cet événement
Ventes terminées
août 7 · 10:00 PDT