IT Security for Web Developers: 2-Day Virtual Seminar (English)

Medien

IT-Sicherheit für Webentwickler: virtueller Zwei-Tage-Workshop - Golem Karrierewelt
IT-Sicherheit für Webentwickler: virtueller Zwei-Tage-Workshop - Golem Karrierewelt

Beschreibung

What does the workshop offer me?

This IT Security workshop teaches web developers how security vulnerabilities arise in web applications and how attackers can exploit them. Participants learn how to identify and avoid common security issues during everyday web development.

The course combines IT Security fundamentals with security concepts for modern web applications. Topics include authentication, encryption, HTTP security, Content Security Policy, OAuth2, OpenID Connect and vulnerability testing.

What will participants learn?

After the workshop, participants can better identify security risks in web applications and apply appropriate security concepts during development.

Participants learn how to:

  • Understand key IT Security principles such as hashing, encryption and encoding
  • Apply authentication and authorization concepts
  • Use HTTP security mechanisms and security-relevant HTTP headers
  • Work with Content Security Policy, JWT, OAuth2 and OpenID Connect
  • Secure forms, file uploads and REST APIs
  • Recognize common attacks from the OWASP Top 10
  • Understand XSS, CSRF, injection and credential attacks
  • Apply strategies against Denial-of-Service attacks
  • Use manual and automated approaches for vulnerability testing
  • Apply static and dynamic analysis to identify vulnerabilities

Who is the course suitable for?

The IT Security workshop is aimed at web developers and software developers who implement, design or evaluate web applications in the frontend or backend.

Participants should have a solid understanding of:

  • HTTP
  • HTML
  • Basic JavaScript
  • Ideally, a dynamic backend programming language

The workshop is designed for experienced developers who want to deepen their knowledge of IT Security and secure web development.

What do participants receive?

Participants attend a two-day live online seminar focused on IT Security for web applications.

They receive:

  • Two days of live online training
  • Access to the seminar via video conference
  • Access information sent by email before the workshop
  • Training in a small group of 4 to 12 participants
  • Practical knowledge for securing frontend, backend and API development

Why this workshop?

Security vulnerabilities often originate during application development. This workshop helps web developers understand these vulnerabilities and consider IT Security directly when designing and implementing web applications.

The course covers both attack techniques and defensive security concepts. Participants also learn how vulnerability testing can be used to identify security issues in web applications.

Agenda

IT Security Basics

  • Security principles
  • Hashing/Encryption/Encoding
  • Symmetric / asymmetric encryption
  • Authentication & Authorization
  • Important Algorithms & Principles

Security Concepts in Web Applications

  • Same Origin Policy
  • Cookie Security (Cookie attributes like httpOnly)
  • HTTP Security
  • Proper Use of Security-Relevant HTTP Headers
  • Content Security Policy (CSP)
  • Transport Encryption
  • Proper Use of Two-Factor Authentication
  • JWT
  • OAuth2 and OpenID Connect
    etc.

Practical Application of Security Concepts

  • How to Ensure Data Integrity, Even When
    • Data Runs Over Unsecure Channels
    • Securing the Communication Path
  • What to Consider
    • When Implementing Authentication
    • Storing Passwords Securely
    • Using a Web Framework
  • Secure Implementation of
    • Forms and File Uploads
    • Denial-of-Service Protection Strategies
    • Security Measures for the Frontend and
    • Secure API Development, Including REST Services

Attacks on Web Applications

  • OWASP Top 10
  • Credential Attacks
  • Cross-Site Scripting
  • Cross Site Request Forgery (CSRF)
  • Various Injection Attacks (e.g., SQL)
  • DoS

Securing Web Applications

  • Against the Introduced Attack Vectors

Introduction to Vulnerability Testing of a Web Application

  • Manual and Automatic Tools
  • Static and Dynamic Analysis for Scanning Vulnerabilities

Dozent

Martina Kraus

Martina Kraus, Google Developer Expert und erfahrene Frontend-Entwicklerin, hat sich auf Webtechnologien und Angular spezialisiert. Sie arbeitet als IT-Trainerin und präsentiert ihr Wissen auf internationalen Konferenzen. Martina ist außerdem an der Organisation von Community-Events wie den Angular Girls und dem Angular Heidelberg Meetup beteiligt.

Weitere Trainings des Dozenten:

Auf einen Blick

Was lerne ich in diesem Kurs?

  • Hashing, encryption, encoding, HMAC, authentication & authorization
  • Same Origin Policy, cookie / HTTP security
  • CSP, 2FA, JWT, OAuth2 & OpenID Connect
  • Forms & file uploads, REST services
  • OWASP Top 10, credential attacks, XSS, CSRF, injection attacks, DoS

Worum geht es in dem "IT Security for Web Developers: 2-Day Virtual Seminar (English)"?

Bei "IT Security for Web Developers: 2-Day Virtual Seminar (English)" geht es um Same Origin Policy, cookie / HTTP security und CSP, 2FA, JWT, OAuth2 & OpenID Connect.

Um welche Art von Training handelt es sich?

Dies ist ein Workshop Training mit interaktiven Sitzungen und praktischem Lernen.

Welches Erfahrungsniveau ist erforderlich?

Dieser Kurs richtet sich an fortgeschrittene Lernende, die bereits über Grundkenntnisse verfügen.

Wer ist der Dozent?

Martina Kraus

Martina Kraus, Google Developer Expert und erfahrene Frontend-Entwicklerin, hat sich auf Webtechnologien und Angular spezialisiert. Sie arbeitet als IT-Trainerin und präsentiert ihr Wissen auf internationalen Konferenzen. Martina ist außerdem an der Organisation von Community-Events wie den Angular Girls und dem Angular Heidelberg Meetup beteiligt.

Wie viel kostet es?

Der Preis beträgt 1.500,00 EUR.

Customer Reviews

Based on 2 reviews
100%
(2)
0%
(0)
0%
(0)
0%
(0)
0%
(0)
H
Hamad Rizwan, e.solutions GmbH

The content was well-structured and highly informative, with practical exercises that reinforced the concepts. The trainer, Martina, was knowledgeable and approachable, creating a great learning atmosphere. I feel much more confident in applying IT security best practices to my work.

A
Anonymous

it was great, personally I knew 80% of the content, so I expected maybe a little more details, but generally I can imagine it was good for other people in the team. I leaned something as well and I'm happy with that :)

Datum
Uhrzeit

1.785,00 EUR inkl. MwSt./USt
1.500,00 EUR zzgl. MwSt./USt.