top of page

Mon, 27 May

|

Singapore, exact location to-be-announced

SINCON 2024 — WEB-300 LIVE Training: Advanced Web Attacks & Exploitation by OffSec

Advanced Web Attacks and exploitation (WEB-300) is an advanced web application security course that teaches the skills needed to conduct white box web app penetration tests.

SINCON 2024 — WEB-300 LIVE Training: Advanced Web Attacks & Exploitation by OffSec
SINCON 2024 — WEB-300 LIVE Training: Advanced Web Attacks & Exploitation by OffSec

Time & Location

27 May 2024, 8:30 am – 31 May 2024, 6:00 pm

Singapore, exact location to-be-announced

About the event

Advanced Web Attacks and Exploitation (WEB-300) is an advanced web application security course that teaches the skills needed to conduct white box web app penetration tests. Learners who complete the course and pass the exam earn the OffSec Web Expert (OSWE) certification and will demonstrate mastery in exploiting front-facing web apps. The OSWE is one of three certifications making up the OSCE3 certification along with the OSEP for advanced pentesting and OSED for exploit development.

TRAINING PRICE

  • Super Early Bird: $7,500 USD (Sign up by 30 September 2023)
  • Early Bird: $8,000 USD (Sign up by 16 February 2024)
  • Standard: $9,200 USD (Sign up by 05 May 2024)
  • Late: $11,100 USD

BENEFITS

Learners will learn how to:

  • Perform a deep analysis on decompiled web app source code
  • Identify logical vulnerabilities that many enterprise scanners are unable to detect
  • Combine logical vulnerabilities to create a proof of concept on a web app
  • Exploit vulnerabilities by chaining them into complex attacks

WHO IS THIS COURSE FOR?

  • Experienced penetration testers who want to better understand white box web app pentesting
  • Web application security specialists
  • Web professionals working with the codebase and security infrastructure of a web application

PREREQUISITES

  • Comfort reading and writing at least one coding language
  • Familiarity with Linux
  • Ability to write simple Python / Perl / PHP / Bash scripts
  • Experience with web proxies
  • General understanding of web app attack vectors, theory, and practice

SYLLABUS

The course covers the following topics.

  • Cross-Origin Resource Sharing (CORS) with CSRF and RCE
  • JavaScript Prototype Pollution
  • Advanced Server-Side Request Forgery (SSRF)
  • Web security tools and methodologies
  • Source code analysis
  • Persistent cross-site scripting
  • Session hijacking
  • .NET deserialization
  • Remote code execution
  • Blind SQL injection
  • Data exfiltration
  • Bypassing file upload restrictions and file extension filters
  • PHP type juggling with loose comparisons
  • PostgreSQL Extension and User Defined Functions
  • Bypassing REGEX restrictions
  • Magic hashes
  • Bypassing character restrictions
  • UDF reverse shells
  • PostgreSQL large objects
  • DOM-based cross site scripting (black box)
  • Server-side template injection
  • Weak random token generation
  • XML external entity injection
  • RCE via database functions
  • OS command injection via WebSockets (black box)

View the full syllabus.

WHAT COMPETENCIES WILL YOU GAIN?

  • Performing advanced web app source code auditing
  • Analyzing code, writing scripts, and exploiting web vulnerabilities
  • Implementing multi-step, chained attacks using multiple vulnerabilities
  • Using creative and lateral thinking to determine innovative ways of exploiting web vulnerabilities

SUPPORTING YOUR JOURNEY

  • 10-hour video series
  • PDF course guide (410+ pages)
  • Private labs
  • Active learner forums
  • Access to the virtual lab environment
  • FREE 90 DAYS LAB ACCESS ONLINE COURSE + 1 CERT EXAM ATTEMPT
  • FREE 6-MONTHS ALL ACCESS LEARN UNLIMITED SUBSCRIPTION (worth ~$3,000 USD)
  • Complimentary OffSec Merchandise (View here)

TRAINER PROFILE 

Nassereddine Abdelli

Nassereddine (Nasro) a Technical Trainer at OffSec, has a decade of professional information security experience in both the offensive and defensive fields, he ran his own online information security learning platform prior to joining OffSec and is always working on something infosec related in his free time.

Tickets

  • Super Early Bird

    US$7,500.00
    Tax: +US$675.00 GST
    Sale ended
  • Early Bird

    US$8,000.00
    Tax: +US$720.00 GST
    Sale ended
  • Standard

    US$9,200.00
    Tax: +US$828.00 GST
    Sale ended
  • Late

    Sale ends: 26 May, 12:00 am
    US$11,100.00
    Tax: +US$999.00 GST

Total

US$0.00

Share this event

Event Info: Events
bottom of page