GOTO Berlin 2019

Tuesday Oct 22
09:00 –
A 05

Building Secure APIs and Web Applications

Student Requirements:
Familiarity with the technical details of building web applications and web services from a software engineering point of view.

The major cause of webservice and web application insecurity is a lack of secure software development knowledge and practices. This highly intensive and interactive 1-day workshop provides essential application security training for web application and webservice developers.

This workshop is a combination of lecture, security testing demonstration and code review. Students will learn the most common threats against applications. More importantly, students will learn how to code secure web solutions via defense-based code samples.

As part of this workshop, we will explore the use of third-party security libraries and frameworks to speed and standardize secure development. We will highlight production quality and scalable controls from various languages and frameworks. This course will include secure coding information for Java, PHP, Python, Javascript and .NET programmers, but any software developer building web applications and webservices will benefit.

Topic will include:
Introduction to Application Security OWASP Top Ten 2017 OWASP ASVS 4.0 HTTP Security Basics XSS Defense Intro to Angular.JS Security Intro to React.JS Security SQL and other Injection Cross Site Request Forgery Input Validation Basics Webservice Security