select a course
Washington, DC - August 15 - 18, 2007
Global Information Assurance Certification
The information presented is priceless!
-Nehal Parmar, North Fork Bank
Security 519


(Portal Account Required)

For GIAC STAR
If you register for the full course, you may register to seek your STAR .
Online exam issued with 4-month deadline 7-10 days following conference.
Additional information:
STAR Information
GIAC FAQ
Fee Information
For OnDemand Bundles
You can bundle SANS OnDemand online training and assessment package for an additional $179.00 US when registering for the full course. Additional information can be found at the OnDemand Bundles page and the OnDemand FAQ.
About
SANS WhatWorks Summit Series
The SANS WhatWorks Summit Series brings together the thought leaders of the industry...
>> Read More
Work Study opportunities still available for WhatWorks in Application Security Summit 2007. Please visit
Work Study Facilitator Page to submit an application.
Learn more about Secure Applications at
SANS SSI
From a mere 26 Web servers operating in November 1992 growing to well over 100 million Web sites today, we have come a long way in Web technology over a short period of time. Today, almost every organization has its own Web site for conducting business transactions or other critical functions. And for many companies, their online presence has become a major revenue generator. As everyone jumps on the bandwagon to do business on the Web, many problems can arise which are directly related to the security aspects of Web applications. The adage "where there is money, there is crime" has become true on a daily basis as we see credit cards and other financial data compromised through Web application vulnerabilities. And that is not even the full extent of the problem because Web-based malware and worms are still spreading in the wild.
How do you protect your Web applications? Our Web application security workshop is a 2-day hands-on, action packed course covering the common vulnerabilities that are leveraged by attackers, the principles of securing Web applications, and general defense techniques to protect against future attacks. This course will help you understand the mechanics of the components necessary for effective Web application security which will then enable you to properly defend your organization's assets.
This course is particularly well suited to developers, QA analysts, and infrastructure security professionals who have an interest in exploring the Web application security world. With the information you learn in this class, you will be able to perform basic security testing on Web applications, as well as architect, design and develop more secure Web applications.
- Who Should Attend
- Web application system and security administrators
- QA analysts who want to learn the mechanics of web applications for better testing
- Anyone interested in techniques for securing Web applications
- Sampling of topics
- Securing web application architectures and infrastructures
- Cryptography
- Authentication
- Access control
- Session mechanism
- Web application logging
- Input issues and validation
- SQL injection
- Cross-Site Scripting
- Phishing
- HTTP Response Splitting
- Cross-Site Request Forgery
Since I am fresh out of college this was a definite eye opener. This course was very valuable in that it gives a view of most tools available for auditing networks.
-Ryan Awai, Eisner LLP