Difference between revisions of "Assessing and Exploiting Web Applications with Samurai-WTF"

From OWASP
Jump to: navigation, search
(Created page with '__NOTOC__ link=http://www.owasp.org/index.php?title=OWASP_AppSec_DC_2010 [https://guest.cvent.com/EVENTS/Register/IdentityConfirmation.aspx?e=…')
 
(Description: updated at Justin's request)
Line 7: Line 7:
 
'''Course Length: 2 Days'''
 
'''Course Length: 2 Days'''
  
This course focuses on using open source tools to perform web application assessments.  The course will take attendees through the process of application assessment using the open source tools included in the Samurai Web Testing Framework Live CD (SamuraiWTF).  After a quick overview of web app pentesting methodology, the instructor will lead attendees through the penetration and exploitation of three different web applications and the browsers connecting to them.  Different sets of open source tools will be used on each web application to introduce a greater number of tools and allow each attendee to learn first hand the pros and cons of each tool.  After attendees have gained experience with the SamuraiWTF tools, the instructor will unleash the class on a fourth web application, challenging the attendees to practice the skills they have gained and experiment with their favorite tools.  The latest tools and techniques will be use throughout the course, including several tools developed by the trainers themselves.
+
Come take the official Samurai-WTF training course given by one of the founders and lead developers of the project!  You will learn how to use the latest Samurai-WTF open source tools and the be shown the latest techniques to perform web application assessments.  After a quick overview of pen testing methodology, the instructor will lead you through the penetration and exploitation of two different web applications, including client side attacks on the browsers connecting to those sites.  Different sets of open source tools will be used on each web application, allow you to learn first hand the pros and cons of each tool.  After you have gained experience with the Samurai-WTF tools, you will be challenged with a third web application.  This final challenge will give you time to practice your new skills at your own pace and experiment with your favorite new tools.  This experience will help you gain the confidence necessary to perform web application assessments and expose you to the wealth of freely available, open source tools.
  
 
==Student Requirements==
 
==Student Requirements==

Revision as of 20:41, 26 September 2010

468x60-banner-2010.gif

Registration | Hotel | Walter E. Washington Convention Center

Description

Course Length: 2 Days

Come take the official Samurai-WTF training course given by one of the founders and lead developers of the project! You will learn how to use the latest Samurai-WTF open source tools and the be shown the latest techniques to perform web application assessments. After a quick overview of pen testing methodology, the instructor will lead you through the penetration and exploitation of two different web applications, including client side attacks on the browsers connecting to those sites. Different sets of open source tools will be used on each web application, allow you to learn first hand the pros and cons of each tool. After you have gained experience with the Samurai-WTF tools, you will be challenged with a third web application. This final challenge will give you time to practice your new skills at your own pace and experiment with your favorite new tools. This experience will help you gain the confidence necessary to perform web application assessments and expose you to the wealth of freely available, open source tools.

Student Requirements

Students Need to Bring:

  1. Laptop with a functional DVD drive or the latest VMware Player, VMware Workstation, or VMware Server installed
  2. Ability to disable all security software on their laptop such as Antivirus and/or firewalls
  3. Four (4) GB of hard drive space
  4. At least two (2) GB of RAM


Objectives

Skill: Intermediate

  1. Attendees will be able to explain the steps and methodology used in performing web application assessments and penetration tests.
  2. Attendees will be able to use the open source tools on the Samurai-WTF CD to discover and identify vulnerabilities in web applications.
  3. Attendees will be able to exploit several client-side and server-side vulnerabilities.


Instructor

Instructor: Justin Searle Justin Searle, a Senior Security Analyst with InGuardians, specializing in the penetration testing of web applications, networks, and embedded devices. Justin currently leads the Smart Grid Security Architecture group of the CSWG (Cyber Security Work Group) for NIST (National Institute of Standards and Technologies) and is a member of ASAP-SG (Advanced Security Acceleration Project for the Smart Grid). Previously, Justin has served as JetBlue Airway’s IT Security Architect. Justin has taught courses in hacking techniques, forensics, networking, and intrusion detection for multiple universities and corporations. Justin has presented at top security conferences including DEFCON, ToorCon, ShmooCon, and SANS. Justin co-leads prominent open source projects including the Samurai-WTF (Web Testing Framework…), Middler, Yokoso!, and Laudnum. Justin has an MBA in International Technology and is CISSP and SANS GIAC-certified in incident handling and hacker techniques (GCIH) and intrusion analysis (GCIA).

Instructor: Mike Poor Mike Poor is a founder and Senior Security Analyst with InGuardians. Mike conducts forensic analysis, penetration tests, vulnerability assessments, security audits and architecture reviews. His primary job focus however is in intrusion detection, response, and mitigation. Mike is an author and editor of the international best seller “Snort 2.1” book from Syngress, and is a Handler for the Internet Storm Center. Mike teaches Intrusion Detection for the SANS Institute and has supported Intrusion Detection and Incident Response teams for the military, and has worked for Sourcefire as a research engineer, and for the SANS Institute leading their Intrusion Analysis Team.]]