The most trusted source for computer security training, certification and research.



select a course
Las Vegas, NV - May 31 - June 9, 2008
Global Information Assurance Certification

GIAC certs are concerned with real applications and principles, rather than vendor products and implementations.
-Rob VandenBrink


Additional Summit Offered in Las Vegas: Two Great Summits! Please visit the WhatWorks in Web Application Security Summit 2008 page for more information.

SECURITY 519

Web Application Security Workshop

Wednesday, June 4, 2008 - Thursday, June 5, 2008 : 9am - 5pm
Johannes Ullrich, PhD, SANS Certified Instructor
6 CPE Credits per day

From a mere 26 Web servers operating in November 1992 growing to well over 100 million Web sites today, we have come a long way in Web technology over a short period of time. Today, almost every organization has its own Web site for conducting business transactions or other critical functions. And for many companies, their online presence has become a major revenue generator. As everyone jumps on the bandwagon to do business on the Web, many problems can arise which are directly related to the security aspects of Web applications. The adage "where there is money, there is crime" has become true on a daily basis as we see credit cards and other financial data compromised through Web application vulnerabilities. And that is not even the full extent of the problem because Web-based malware and worms are still spreading in the wild.

How do you protect your Web applications? Our Web application security workshop is a 2-day hands-on, action packed course covering the common vulnerabilities that are leveraged by attackers, the principles of securing Web applications, and general defense techniques to protect against future attacks. This course will help you understand the mechanics of the components necessary for effective Web application security which will then enable you to properly defend your organization's assets.

This course is particularly well suited to developers, QA analysts, and infrastructure security professionals who have an interest in exploring the Web application security world. With the information you learn in this class, you will be able to perform basic security testing on Web applications, as well as architect, design and develop more secure Web applications.

  • Who Should Attend
    • Web application system and security administrators
    • QA analysts who want to learn the mechanics of web applications for better testing
    • Anyone interested in techniques for securing Web applications
  • Sampling of topics
    • Securing web application architectures and infrastructures
    • Cryptography
    • Authentication
    • Access control
    • Session mechanism
    • Web application logging
    • Input issues and validation
    • SQL injection
    • Cross-Site Scripting
    • Phishing
    • HTTP Response Splitting
    • Cross-Site Request Forgery

Attending a SANS conference provides attendees with a great opportunity to learn from and share with world class IS Security professionals at a reasonable cost.
-Theresa Wahl, USAF