Skip to main content
EduRails

Online learning made easy. For your whole institution.

AdvancedContent in Spanish

Web application security (OWASP)

Learn to build resilient web applications from the perspective of the defending developer. This course covers the OWASP Top 10 (injection, broken authentication, XSS, broken access control and IDOR, SSRF, security misconfiguration and insecure deserialization) and connects it with secure coding practices: threat modeling, input validation and sanitization, secure session and JWT handling, secrets management, dependency security (SCA), SAST, DAST, security headers and a secure development lifecycle (SSDLC). It is the fourth course of the Professional Certificate in Cybersecurity.

9 lessons 12 hours 900 XP

Start the course

Syllabus

Module 1 · AppSec fundamentals and threat modeling

  1. 1Threat modeling and the secure development lifecycle (SSDLC)50 min
  2. 2Input validation and sanitization50 min

Module 2 · OWASP Top 10: the major attack vectors

  1. 3Injection: SQL, NoSQL and OS commands55 min
  2. 4Cross-Site Scripting (XSS): reflected, stored and DOM-based55 min
  3. 5Broken access control and IDOR55 min
  4. 6SSRF, security misconfiguration and insecure deserialization55 min

Module 3 · Authentication, sessions and secrets

  1. 7Secure session and JWT management55 min
  2. 8Secrets management and credential storage50 min

Module 4 · Continuous defense: dependencies, testing and headers

  1. 9Dependency security (SCA), SAST/DAST and security headers55 min

Back to the catalogue