0% found this document useful (0 votes)
4 views2 pages

Security

qwndwenfncw w wkfkjwenfn wfkjjwejkf wjfe jkwef
Copyright
© All Rights Reserved
We take content rights seriously. If you suspect this is your content, claim it here.
Available Formats
Download as TXT, PDF, TXT or read online on Scribd
0% found this document useful (0 votes)
4 views2 pages

Security

qwndwenfncw w wkfkjwenfn wfkjjwejkf wjfe jkwef
Copyright
© All Rights Reserved
We take content rights seriously. If you suspect this is your content, claim it here.
Available Formats
Download as TXT, PDF, TXT or read online on Scribd

----------------------------------

20 marks

Sources:
1) Sir Notes
2) Text Book

--------------------------------
Session 1:

• Web Application Security Risks


• Identifying the Application Security Risks
• Guide line for providing security for web application Lab 1
• Different method for finding the web application vulnerability

--------------------------------
Session 2:

• Data Extraction
• Advanced Identification/Exploitation
• Foundation of Security(Identification, Authentication, Authorization, Access
Control)

Lab 2
• Email data Extraction from targeted URL
• Deleted Database data extraction
• Extracting a data from DUMP.
• Offline authentication, Mutual authentication, Message Authentication(MAC, HMAC,
GMAC)

-------------------------------
Session 3:

• Classic SDLC model


• Secure Software Development Life Cycle

-------------------------------
Session 4:

• PKI
• Cryptographic algorithms
• Types of symmetric key and Asymmetric key algorithms
• Digital Signature, Hash function,

Lab 3
• Generate certificate for SSH communication.
• Generate Digital signature for Authentication
• Deployment of Kerberos

----------------------------------
Session 5:

• Other HTTP fields


• Injection in stored procedures
• Threat Risk Modelling
• OWASP Top 10 of 2017

Lab 4
• Broken authentication and session management
• Security Misconfiguration
• Using component with known vulnerability

-----------------------------------
Session 6:

• Threat, vulnerability and attack identification


• Injection and Inclusion

----------------------------------
Session 7:

• Buffer Overflows and Input Validation


• Access Control

Lab 5 & 6 :
• Broken Access Control
• Sensitive Data Exposer
• Insufficient attack protection

------------------------------------
Session 8:

• SQL, OS, XXE injection


• Cross site scripting
• Case Study On Web Application Framework

Lab 7:
• XSS
• SQL injection techniques
• Cross site request Forgery (CSRF)

-------------------------------------
Session 9:

• Web DOS attack


• Types of DOS attack
• DOS and DDOS
• Attacker motivation

Lab 8:
• Identify the DOS attack and mitigation for DOS

------------------------------------
Session 10:
• Web server Security
• Performance Testing

Lab 9 & 10:


• Build your secure application with removing all know vulnerability
• Build your website with all included authentication and authorization
certificate.

------------------------------------

You might also like