The days of porous network perimeters are fading fast as services become more resilient and harder to exploit. In order to gain that initial critical foothold in a network, penetration testers must be fluent in the art of exploiting front-facing web applications.
Offensive Security's Advanced Web Attacks and Exploitation was created by taking widely deployed web applications found in many enterprises and actively exploiting them. This intensive, hands-on course takes your skills beyond run-of-the-mill SQL injection or mediocre file inclusion attacks and propels you into a world of brain-melting SQL queries, mind-blowing XSS and remote code execution attacks รข" starting from that initial foothold and ending with a complete compromise.
Topics covered include:
Advanced Web Attacks and Exploitation is NOT an entry level course. The pace of learning is fast and furious - students are expected to have a solid understanding of how to perform basic web application attacks, at a minimum. This class is perfect for experienced network penetration testers who are looking to take their web application penetration testing skills to the next level, as well as web application developers who need to understand how their code is attacked.
It is assumed that the student already has a medium understanding of the underlying protocols and technologies involved in testing web applications such as the HTTP protocol, SSL communications, and the usage of various browser plugins and proxies. A basic familiarity with web based programming languages such as PHP, JavaScript and MySQL will also prove helpful.
Students are required to bring their own laptops with:
Students will be provided with virtual machines for use in class. Additionally, the Advanced Web Attacks and Exploitation lab guide will be provided. An in-class "Hint System" will provide electronic distribution of all scripts, POCs, and so on.
Mati Aharoni is deeply involved in the security community and has laid several corner stones in the community, such as the Exploit Database, the Kali Linux Distribution as well as the industry leader of practical, hands-on, information security training - Offensive Security. Mati is also the creator and lead instructor of the Advanced Web Attacks and Exploitation class - which has been the first class to sell out at Black Hat Vegas consecutively since its premier three years ago.