Special offers now — see discounted courses.
day
:
hour
:
min
:
sec
See special offers
Dynamic Application Security Testing (DAST) (2019)

Dynamic Application Security Testing (DAST) (2019)

3h 20mIntermediate2019-08-07

Authors

Jerod Brennen

Jerod Brennen

Security Architect, Advisor, Speaker, Teacher

Course details

Building security testing into the software development life cycle is the best way to protect your app and your end users. This course identifies tools and techniques that developers can use to minimize the cost and impact of security testing—while maximizing its impact and effectiveness. In this course, instructor Jerod Brennen focuses on online testing, using security scanning, penetration testing, and vulnerability testing to validate code and uncover vulnerabilities. He explains the difference between positive and negative, manual and automated, and production and nonproduction testing, so you can choose the right kind for your workflow. The hands-on sections—with demos of popular tools such as Fiddler, Burp Suite, and OWASP OWTF—prepare you to apply the lessons in the real world.

Learning objectives
Positive and negative testing
OWASP Testing Guide
Manual vs. automated testing
Scanning vs. pen testing
Testing in the right environment
Pen testing a web app
Evading SIEMs
Coordinating red and blue teams
Testing for OWASP Top Ten vulnerabilities

Skills covered

Application SecurityEssential TrainingCybersecurity

Concepts

0. Introduction

  • 01 - The importance of online testing
  • 02 - What you should know

1. Security Testing in QA

  • 03 - Software quality assurance process
  • 04 - Positive testing
  • 05 - Negative testing
  • 06 - SQA metrics
  • 07 - OWASP Testing Guide
  • 08 - Demo - OWASP ZAP

2. Assessing Deployed Apps

  • 09 - Manual vs. automated testing
  • 10 - Scanning vs. pen testing
  • 11 - Testing in non-production
  • 12 - Testing in production
  • 13 - OSINT gathering
  • 14 - Web app proxies
  • 15 - Demo - Fiddler2
  • 16 - Demo - Burp Suite
  • 17 - Demo - Samurai Web Testing Framework (WTF)

3. Web App Pen Testing

  • 18 - Scoping a web app pen test
  • 19 - Avoiding production impacts
  • 20 - The penetration testing execution standard
  • 21 - Types of pen tests
  • 22 - Web application firewalls
  • 23 - SIEMs
  • 24 - Purple teaming
  • 25 - Demo - OWASP OWTF

4. Testing for the OWASP Top Ten (2017)

  • 26 - The OWASP Top Ten
  • 27 - A1 - Injection
  • 28 - A2 - Broken authentication
  • 29 - A3 - Sensitive data exposure
  • 30 - A4 - XML external entities (XXE)
  • 31 - A5 - Broken access control
  • 32 - A6 - Security misconfiguration
  • 33 - A7 - Cross-site scripting (XSS)
  • 34 - A8 - Insecure deserialization
  • 35 - A9 - Using components with known vulnerabilities
  • 36 - A10 - Insufficient logging and monitoring

Conclusion

  • 37 - Next steps

About us

LyndaKade is a leading learning platform that helps people learn business, software, technology, and creative skills to achieve personal and professional goals.

Phone numberAparat ChannelTelegram SupportTelegram ChannelInstagram Page

All rights to this site belong to LyndaKade.

Terms of Service|Privacy Policy

نماد الکترونیک enamad در صورت اتصال با آی‌پی داخل کشور، نمایش داده خواهد شد.
logo-samandehi - لوگو ساماندهی
Zarinpal
Zibal