AdvancedContent in Spanish
Web application security (OWASP)
Learn to build resilient web applications from the perspective of the defending developer. This course covers the OWASP Top 10 (injection, broken authentication, XSS, broken access control and IDOR, SSRF, security misconfiguration and insecure deserialization) and connects it with secure coding practices: threat modeling, input validation and sanitization, secure session and JWT handling, secrets management, dependency security (SCA), SAST, DAST, security headers and a secure development lifecycle (SSDLC). It is the fourth course of the Professional Certificate in Cybersecurity.
9 lessons 12 hours 900 XP
Start the courseSyllabus
Module 1 · AppSec fundamentals and threat modeling
- 1Threat modeling and the secure development lifecycle (SSDLC)50 min
- 2Input validation and sanitization50 min
Module 2 · OWASP Top 10: the major attack vectors
- 3Injection: SQL, NoSQL and OS commands55 min
- 4Cross-Site Scripting (XSS): reflected, stored and DOM-based55 min
- 5Broken access control and IDOR55 min
- 6SSRF, security misconfiguration and insecure deserialization55 min
Module 3 · Authentication, sessions and secrets
- 7Secure session and JWT management55 min
- 8Secrets management and credential storage50 min
Module 4 · Continuous defense: dependencies, testing and headers
- 9Dependency security (SCA), SAST/DAST and security headers55 min