About UsContact UsAdvertise on Test RepublicQuick Register For Any ETI EventPress RoomJoin Mailing List
Edista Testing Institute   Home Home Send Mail Send Mail    
   UPCOMING EVENTS
  Training Public Programs - India Web Application Security Testing  
     
 
2 Day Public Program Email this page
 
Print this Page
     

Target Audience

The course is appropriate for both Novice and Experienced Testers under the following category: Test Engineers who are not familiar with Web Application Security Testing but have fundamental knowledge/experience in functional testing.

Benefits of this course:

After the completion of the course, the participants would be able to:

Learn how attackers succeed in breaking web applications
Understand the attack target possibilities of web apps
Understand and apply the differences between Security testing & Functional testing
Gain basic network/system level knowledge needed for application security testers
Understand the 'Top Ten' vulnerabilities proposed by OWASP
Get hands-on Web Application Security Testing techniques, using WebScarab and other tools
Incorporate security testing as a continuous process in your organization

Details of Topics covered:

Day One

Introduction
What is Security
Grasping the fundamentals of Security flaws
Vulnerabilities and the anatomy of an attack
Some proven application security principles
The mindset needed for Testing the Security aspects of a web application

Review of Top Ten vulnerabilities in Web Applications
Cross Site Scripting (XSS)
Injection Flaws
Malicious File Execution
Insecure Direct Object Reference
Cross Site Request Forgery (CSRF)


Review of Top Ten vulnerabilities in Web Applications
Information Leakage and Improper Error Handling
Broken Authentication and Session Management
Insecure Cryptographic Storage
Insecure Communications
Failure to Restrict URL Access

Grasping the bastic system-level knowledge
How the network plays a role between clients and servers
Basic network commands that testers need to know
(Handson)Understanding the elements of a web application, with focus on the HTTP data
Overview of HTTP Requests/Responses
Concept of cookies, revisited
Using Fiddler

Day Two
Practical session on testing web application security
Discussions

Introduction to Web Scarab
Understanding the context of tools
Introduction to Web Scarab

HTTP Request Interception & Manipulation
Using a proxy to intercept the request
Adding custom fields dynamically

Practical demo on Cross Site Scripting vulnerability identification
Using Web Scarab to analyze URLs
Injecting Javascript into request prameters

Inferences and HTML fields as sources of Attacks
Revealing Hidden Fields
Exceptions as the basis of knowing the server environment

Fuzzing and Web Application Security Testing
General concepts of fuzzers
Parameter fuzzing in web applications
Practical Demonstration of SQL Injection

Exercises on Web Application Testing

About Instructor
Ashiwn Palaparthi has 10+ years of experience in Test Engineering. He has worked at AppLabs for 6 years and held several positions starting from a Project Lead to Manager to Principal Architect to Associate Vice President. At Applabs he was deeply involved in technology support to Test Engineering, custom tools development and presales.

To his credit, Ashwin has
- built automated unit test suite for ZENEB’s compoenent platform.
- performed white-box testing (code/design reviews, profiling, instrumentation etc) for e-Duction.
- developed a prototype extension to Winrunner to support 3rd party ActiveX controls from Infragistics (a famous Activex component vendor).
- developed a Custom Test Harness for a company called Marketaxess, which is being used by 50 testers for last 5 years day-in/day-out without any changes.
- ran a Security Testing Practice as the Practice Head for a group of 100+ engineers in AppLabs where we performed Web-application Security Testing, Testing Security Products themselves etc.
- extended Jmeter and built a framework-assisted Performance Testing service.

Ashwin also delivered two seminars in London, one on Performance Testing using Open-source Testing tools and the other on Security Testing [ICSTEST,2004] and also delivered talks at HYSEA events. He also handled a very complex Test Automation project for ISS, built a custom Test Automation framework using QTP (and automated about 4000 tests, some of which were on distributed environment) for ISS.

Ashwin also created the world’s first Online Tool Platform for Software Testers, TestersDesk.com which today has more than 5000 users and has won the Best Innovation of the Year award among tight competition.

         
Schedule        
Date - City   Venue
April 09 - Apr. 10 · Pune, INDIA
May 07 - May. 08 · Bangalore, INDIA
  To be announced
To be announced
 
Daily Schedule
Registration: 8:30 - 9:30 a.m.
Morning Session 8:30 a.m. - 01:00 p.m.
Lunch 01:00 - 1:45 p.m.
Afternoon Session 1:45 - 5:00 p.m.

This is a typical daily schedule. Please confirm the program schedule at registration.
         
Nomination Fee        
Rs. 10,000 for Single Nomination + 12.36% Service Tax

5% Discount for Early Bird Registrations (15 Days in advance to the program date)
5% Discount on Task force of 4 to 7
10% Discount on task Force of 8 and above
10% discount applicable to CSTE / CSQA Qualified Professionals,
10% discount applicable to PMI / CSI Members and NASSCOM Members


The price includes the course material, lunch & breaks each day, and a certificate of completion. Hotel and travel arrangements are the responsibility of the attendee.

ETI Cancellation Policy
  • All cancellations must be made in writing - either by mail, e-mail, or fax.
  • All payments must be received by ETI prior to the start of the workshop/seminar.
  • If cancelled 5 calendar days, or later, prior to the start date or for no-shows - NO REFUND
  • If cancelled 6-30 calendar days prior to the start date - 50 % of the workshop/seminar fee will be non-refundable.
  • If cancelled prior to 30 calendar days to the start date - A full refund will be issued.
  • You are welcome to substitute if you cannot attend, but please notify in advance.
  • You may reschedule with at least four weeks notice prior to the workshop/seminar for which you are currently registered.
  • Please send all cancellations and substitutions to training@edistatesting.com or call 91-80-415-74806, Attn: Workshop Coordinator
To register, please call 91-80-415-74806 or 91-80-415-74807, or email us at training@edistatesting.com.
 
 

Need to train multiple people on this topic? Try private in-house training.
For more information contact Akshay Raj at akshay.r@edistatesting.com or 91-80-415-74806

 
 
         

  
India India

Web Application Security Testing
April 09 - Apr. 10 · Pune, INDIA
May 07 - May. 08 · Bangalore, INDIA

Agile Test Strategies and Management
June 11 – Jun 12 · Chennai, INDIA
June 23 – Jun 24 · Hyderabad, INDIA

Exploratory Testing – A Rapid Software Testing Approach
April 23 – Apr 24 · Hyderabad
June 03 – Jun 04 · Pune, INDIA
June 16 – Jun 17 · Bangalore, INDIA

Advanced Test Case Design
May 07 – May 08 · Chennai, INDIA
May 12 – May 13 · Hyderabad, INDIA
June 08 – Jun 09 · Bangalore, INDIA

Advanced Learning of QTP 9.2
April 07 – Apr 08. Chennai, INDIA

CSTE Preparatory Training
April 28 – Apr 30. Bangalore, INDIA

Agile Scrum Practitioner
April 02 – Apr 03 · Hyderabad, INDIA
May 06 – May 07 · Pune, INDIA
May 18 – May 19 · Bangalore, INDIA

Requirements Based Testing
April 22 – Apr 23 · Bangalore, INDIA
May 26 – May 27 · Pune, INDIA
June 09 – Jun 10 · Hyderabad, INDIA

Practical Estimation of Testing Projects
April 23 – Apr 24. Chennai, INDIA
May 14 – May 15. Pune, INDIA
June 25 – Jun 26. Bangalore, INDIA

Web Services (SOA) Testing
May 27 – May 28. Hyderabad, INDIA
June 10 – Jun 11. Pune, INDIA
June 25 – Jun 26. Chennai, INDIA
June 29 – Jun 30. Bangalore, INDIA

Testing Multimedia Applications
April 13. Bangalore, INDIA

Designing Effective Tests
April 17 – Apr 18. Pune, INDIA
May 14 - May 15. Pune, INDIA

Manual Testing Skills for Better Productivity
April 16 – Apr 17. Bangalore, INDIA
June 29 – Jun 30. Pune, INDIA

Performance Testing with Load Runner
April 28 – Apr 29. Pune, INDIA
May 27 – May 28. Chennai, INDIA

Test Architecture
May 21 – May 22 · Bangalore, INDIA
June 18 – Jun 19 · Pune, INDIA

Writing Testable Requirements
May 28 – May 29 · Bangalore, INDIA

Check out the 2009-10 Q1 Program Schedule and make your training plans.

By Location | By Country | By Subject Area

Check out the new benefits & products included in our "New" Membership Program for both Corporations and Individuals...

What Do You Want To Do Today?

Register for a course
Be part of the community
Attend a conference
Send a business enquiry
Become Certified
Become a Corporate Member
Partner with Edista

Edista Testing Institute has the capability to meet all your competency assessments, training, certification, elearning, and staffing needs (experienced as well as entry level). Please get in touch with us if you do not find any service/training product on the website that you are looking for.


 
 
A venture of


QAI is Asia’s largest and world’s third largest global consulting organization addressing
‘Operational Excellence' in IT, BPO and Knowledge intensive organizations.

© 2008 Edista Testing Institute. All Rights Reserved.

Contact Us  |  Terms of Use  |  Privacy Statement  |  Careers