Skip to main content
Intake every 3 weeks! There is no "application deadline" — you can start any upcoming module!Intake every 3 weeks! — apply anytime!
Studies
Admissions
The Institute
Resources
Intake every 3 weeks! There is no "application deadline" — you can start any upcoming module!Intake every 3 weeks! — apply anytime!
Studies
Admissions
The Institute
Resources
Intake every 3 weeks! There is no "application deadline" — you can start any upcoming module!Intake every 3 weeks! — apply anytime!
Studies
Admissions
The Institute
Resources

Web Application Security

Barcelona Campus
Mar 09, 2020 - Mar 27, 2020
Web application security is one of the fundamental skills for the modern practical information security specialist.
Barcelona Campus
Mar 09, 2020 - Mar 27, 2020

Faculty Profiles

Alexey Kuznetsov

Alexey Kuznetsov

Head of Penetration Testing services at BI.ZONE

Vladislav Lazarev

Vladislav Lazarev

Head of Penetration Testing at BI.ZONE, CISSP

Course length

3 weeks

Duration

3 hours
per day

Total hours

45 hours

Credits

60 ECTS

Language

English

Course type

Offline

Fee for single course

€1500

Fee for degree students

€750

Skills you’ll learn

Social MediaBig DataAlgorithmsComputer Science
OverviewCourse outlineCourse materialsPrerequisites

Overview

Web application security is one of the fundamental skills for the modern practical information security specialist. The course covers a wide range of topics, from web application vulnerabilities to secure development standards and methodologies. It teaches students to employ a methodological and practical approach to web application penetration testing.

Learning highlights

  • web technology concepts (protocols, network, etc)
  • web application evolution
  • web application development concepts
  • web application architecture
  • web application threat model
  • server-side web application vulnerabilities and defense
  • client-side web application vulnerabilities and defense
  • secure development lifecycle

Course outline

6 classes

Dive into the details of the course and get a sense of what each class will cover.
Monday
Tuesday
Wednesday
Thursday
Friday
Monday
1

Session 1

Introduction. Web application technology and evolution

Tuesday
2

Session 2

Information gathering. Fingerprinting and enumeration

Wednesday
3

Session 3

Server-side vulnerabilities. SQL Injections

Thursday
4

Session 4

Server-side vulnerabilities. XXE and Command and Code Injections

Friday
5

Session 5

Server-side Vulnerabilities. Server-side template injections, PHP and Java Deserialization

Monday
6

Session 6

Server-side Vulnerabilities. Server-side request forgery, Business logic flaws

Prerequisites

This course is one of three in a wholistic series.

Students that have already taken MSL-111 and those with prior experience with HTML, CSS, and Javascript building simple web pages will be good candidates for this module.

Alexey Kuznetsov

Faculty

Alexey Kuznetsov

Head of Penetration Testing services at BI.ZONE

Alexey has more than 6 years of work experience in projects related to Cybersecurity. Currently he is the Head of Penetration testing team in BiZone, subsidiary of Sberbank (the largest Russian bank). His responsibilities involve planning, conducting and reporting penetration testing, as well as security assessment. During his career he designed and developed a wide range of software security systems and conducted some research in the area of hardware virtualization. He is also experienced in mobile application security analysis, web application security auditing. Furthermore, he is interested in IoT information security (connected cars, smart houses, smart city systems) and won a couple of competitions in this area.

Alexey actively participates in CTF competitions. He is also one of the organizers of CTF.Zone contest.

See full profile
Vladislav Lazarev

Faculty

Vladislav Lazarev

Head of Penetration Testing at BI.ZONE, CISSP

Vladislav have more than six years experience in both defensive and offensive information security with a solid background in information security-related software development. He took part in more than 50 penetration testing, red team and vulnerability assessment projects as a penetration tester and a team lead. Vladislav graduated from the National Research Nuclear University MEPhI (Moscow Engineering and Physics Institute) with a degree in information security. Currently he is a Head of Penetration testing in BiZone.

See full profile

Apply for this course

Snap up your chance to enroll before all spaces fill up.

Web Application Security

by Alexey Kuznetsov, Vladislav Lazarev

Total hours

45 Hours

Dates

Mar 09 - Mar 27, 2020

Fee for single course

€1500

Fee for degree students

€750

How to secure your spot

Complete the form below to kickstart your application

Schedule your Harbour.Space interview

If successful, get ready to join us on campus

FAQ

Will I receive a certificate after completion?

Yes. Upon completion of the course, you will receive a certificate signed by the director of the program your course belonged to.

Do I need a visa?

This depends on your case. Please check with the Spanish or Thai consulate in your country of residence about visa requirements. We will do our part to provide you with the necessary documents, such as the Certificate of Enrollment.

Can I get a discount?

Yes. The easiest way to enroll in a course at a discounted price is to register for multiple courses. Registering for multiple courses will reduce the cost per individual course. Please ask the Admissions Office for more information about the other kinds of discounts we offer and what you can do to receive one.