Advanced Application Security Penetration Testing

Web penetration testing for experienced pentesters
This training provides answers to the following questions
- How do I use the advanced features of Burp Suite?
- What else is hidden in standard tools like sqlmap, netcat and nmap?
- How do I test with existing firewalls and WAFs?
- How do I expand my existing toolkit?
Headline 3
Text 3
Details
The training includes a variety of advanced practical exercises, for which our comfortable training environment is used. The vulnerabilities are understood by the participants by solving tasks and then discussed in the group.
The training environment allows participants to use their own laptop with their individual working environment, without artificial adaptation to the training environment. The use of a suitable penetration testing environment, such as Kali Linux or Blackarch, is recommended, but is not a prerequisite.
All content can be specifically adapted for you in consultation with you!
Course content
Fundamentals
- HTTP, DNS
- Sessions, Cookies, Dom Storage
- Ajax/CORS
- CSP
- Cryptography, SSL/TLS
- HSTS
Tools
- Burp (Usage, Session Management, Macros, Writing Extensions)
- ncat, nmap
- sslscan, testssl.sh, o-saft
- sqlmap
Attacks
- XSS Exploitation, DOM-based XSS, Blind XSS
- Injection (SQL, Blind SQLi, LDAP, XML, Code, …)
- Insecure Object Deserialization
- NoSQL Injection
- CSRF in modern web applications
- JSONP Hijacking, CORS Misconfiguration, Websocket Hijacking
- XML External Entity Includes, XSLT
- SSRF
- Logical/Semantic Attacks, Phishing
Defense
- Network segmentation
- Firewalls, WAFs
- IDS/IPS
- Anti-Automation
This training is aimed at companies and organizations. It is individually tailored to your requirements and the team's prior knowledge and can be carried out in-house or online. This training can be economical from as few as three participants.
Target Group
Penetration tester
Duration & Format
- 2 to 5 days, individually tailored
- On-site or online training
Prerequisites
Practical experience as a penetration tester
Our trainers
Our promise: from practice, for practice & always up to date. That's why all our trainers are active experts with many years of experience in the subject area they teach.
Your Benefit
Our training courses not only impart knowledge, they also change mindsets. Your developers will learn to identify security vulnerabilities early on and avoid them in a targeted manner. The result: more robust applications, more confidence - and a clear advantage in everyday project work.
All trainers are actively working Security Consultants. They contribute their experience with everyday problems, which often conflict with security requirements, and thus contribute to a pragmatic, realistic approach to security.
- Practical methods instead of theory to avoid typical security gaps in web applications and mobile apps.
- Content according to the latest standards by actively working, experienced Security Consultants.
- Secure coding for long-term maintainability and quality of the source code.
- Increased security awareness in the team prevents pitfalls at an early stage.
- Protection against liability risks & damage to reputation.





