Web Application Security
Faculty Profiles

Alexey Kuznetsov
Head of Penetration Testing services at BI.ZONE

Vladislav Lazarev
Head of Penetration Testing at BI.ZONE, CISSP
Course length
Duration
Total hours
Credits
Language
Course type
Fee for single course
Fee for degree students
Skills you’ll learn
Overview
Web application security is one of the fundamental skills for the modern practical information security specialist. The course covers a wide range of topics, from web application vulnerabilities to secure development standards and methodologies. It teaches students to employ a methodological and practical approach to web application penetration testing.
Learning highlights
- web technology concepts (protocols, network, etc)
- web application evolution
- web application development concepts
- web application architecture
- web application threat model
- server-side web application vulnerabilities and defense
- client-side web application vulnerabilities and defense
- secure development lifecycle
Course outline
6 classes
Session 1
Introduction. Web application technology and evolution
Session 2
Information gathering. Fingerprinting and enumeration
Session 3
Server-side vulnerabilities. SQL Injections
Session 4
Server-side vulnerabilities. XXE and Command and Code Injections
Session 5
Server-side Vulnerabilities. Server-side template injections, PHP and Java Deserialization
Session 6
Server-side Vulnerabilities. Server-side request forgery, Business logic flaws
Prerequisites
This course is one of three in a wholistic series.
Students that have already taken MSL-111 and those with prior experience with HTML, CSS, and Javascript building simple web pages will be good candidates for this module.
Alexey has more than 6 years of work experience in projects related to Cybersecurity. Currently he is the Head of Penetration testing team in BiZone, subsidiary of Sberbank (the largest Russian bank). His responsibilities involve planning, conducting and reporting penetration testing, as well as security assessment. During his career he designed and developed a wide range of software security systems and conducted some research in the area of hardware virtualization. He is also experienced in mobile application security analysis, web application security auditing. Furthermore, he is interested in IoT information security (connected cars, smart houses, smart city systems) and won a couple of competitions in this area.
Alexey actively participates in CTF competitions. He is also one of the organizers of CTF.Zone contest.
See full profileVladislav have more than six years experience in both defensive and offensive information security with a solid background in information security-related software development. He took part in more than 50 penetration testing, red team and vulnerability assessment projects as a penetration tester and a team lead. Vladislav graduated from the National Research Nuclear University MEPhI (Moscow Engineering and Physics Institute) with a degree in information security. Currently he is a Head of Penetration testing in BiZone.
See full profileApply for this course
Web Application Security
by Alexey Kuznetsov, Vladislav Lazarev
Total hours
45 Hours
Dates
Mar 09 - Mar 27, 2020
Fee for single course
€1500
Fee for degree students
€750
How to secure your spot
Complete the form below to kickstart your application
Schedule your Harbour.Space interview
If successful, get ready to join us on campus
FAQ
Will I receive a certificate after completion?
Yes. Upon completion of the course, you will receive a certificate signed by the director of the program your course belonged to.
Do I need a visa?
This depends on your case. Please check with the Spanish or Thai consulate in your country of residence about visa requirements. We will do our part to provide you with the necessary documents, such as the Certificate of Enrollment.
Can I get a discount?
Yes. The easiest way to enroll in a course at a discounted price is to register for multiple courses. Registering for multiple courses will reduce the cost per individual course. Please ask the Admissions Office for more information about the other kinds of discounts we offer and what you can do to receive one.