What does the workshop offer me?
This IT Security workshop teaches web developers how security vulnerabilities arise in web applications and how attackers can exploit them. Participants learn how to identify and avoid common security issues during everyday web development.
The course combines IT Security fundamentals with security concepts for modern web applications. Topics include authentication, encryption, HTTP security, Content Security Policy, OAuth2, OpenID Connect and vulnerability testing.
What will participants learn?
After the workshop, participants can better identify security risks in web applications and apply appropriate security concepts during development.
Participants learn how to:
- Understand key IT Security principles such as hashing, encryption and encoding
- Apply authentication and authorization concepts
- Use HTTP security mechanisms and security-relevant HTTP headers
- Work with Content Security Policy, JWT, OAuth2 and OpenID Connect
- Secure forms, file uploads and REST APIs
- Recognize common attacks from the OWASP Top 10
- Understand XSS, CSRF, injection and credential attacks
- Apply strategies against Denial-of-Service attacks
- Use manual and automated approaches for vulnerability testing
- Apply static and dynamic analysis to identify vulnerabilities
Who is the course suitable for?
The IT Security workshop is aimed at web developers and software developers who implement, design or evaluate web applications in the frontend or backend.
Participants should have a solid understanding of:
- HTTP
- HTML
- Basic JavaScript
- Ideally, a dynamic backend programming language
The workshop is designed for experienced developers who want to deepen their knowledge of IT Security and secure web development.
What do participants receive?
Participants attend a two-day live online seminar focused on IT Security for web applications.
They receive:
- Two days of live online training
- Access to the seminar via video conference
- Access information sent by email before the workshop
- Training in a small group of 4 to 12 participants
- Practical knowledge for securing frontend, backend and API development
Why this workshop?
Security vulnerabilities often originate during application development. This workshop helps web developers understand these vulnerabilities and consider IT Security directly when designing and implementing web applications.
The course covers both attack techniques and defensive security concepts. Participants also learn how vulnerability testing can be used to identify security issues in web applications.
Agenda
IT Security Basics
- Security principles
- Hashing/Encryption/Encoding
- Symmetric / asymmetric encryption
- Authentication & Authorization
- Important Algorithms & Principles
Security Concepts in Web Applications
- Same Origin Policy
- Cookie Security (Cookie attributes like httpOnly)
- HTTP Security
- Proper Use of Security-Relevant HTTP Headers
- Content Security Policy (CSP)
- Transport Encryption
- Proper Use of Two-Factor Authentication
- JWT
-
OAuth2 and OpenID Connect
etc.
Practical Application of Security Concepts
-
How to Ensure Data Integrity, Even When
- Data Runs Over Unsecure Channels
- Securing the Communication Path
-
What to Consider
- When Implementing Authentication
- Storing Passwords Securely
- Using a Web Framework
-
Secure Implementation of
- Forms and File Uploads
- Denial-of-Service Protection Strategies
- Security Measures for the Frontend and
- Secure API Development, Including REST Services
Attacks on Web Applications
- OWASP Top 10
- Credential Attacks
- Cross-Site Scripting
- Cross Site Request Forgery (CSRF)
- Various Injection Attacks (e.g., SQL)
- DoS
Securing Web Applications
- Against the Introduced Attack Vectors
Introduction to Vulnerability Testing of a Web Application
- Manual and Automatic Tools
- Static and Dynamic Analysis for Scanning Vulnerabilities

