Programme Content
**Web Background:** Motivation, brief history, what constitutes a web page, browser internals, web protocols, session management, server internals. Practical sessions will cover Firefox/Chrome browser developer tools to inspect/edit web pages and network requests and OWASP ZAP for web application security testing **Server Side Attacks and Defense:** Information Disclosure, Server Side Request Forgery (SSRF), Path traversal, File Upload Vulnerabilities, Authentication and Authorization including Oauth, Command Injection, SQL (Structured Query Language) Injection. Practical sessions will explore a subset of these server-side attacks and defenses hands-on. **Client Side Attacks and Defense:** Cross Site Request Forgery (CSRF), Cross Site Scripting (XSS), Cross Origin Resource Sharing (CORS), Web Sockets. Practical sessions will explore a subset of these client-side attacks and defenses hands-on **Web Security Landscape:** Anatomy of web attacks, OWASP top 10, CVE database, and CVSS scores, Overall Defense, Web Application Firewalls and Best Practices. Latest trends in web security.
