{"product_id":"it-security-web-developers-owasp-workshop","title":"IT Security for Web Developers: 2-Day Virtual Seminar (English)","description":"\u003ch2\u003e\u003cspan\u003eWhat does the workshop offer me?\u003c\/span\u003e\u003c\/h2\u003e\n\u003cp\u003e\u003cspan\u003eThis IT Security workshop teaches web developers how security vulnerabilities arise in web applications and how attackers can exploit them. Participants learn how to identify and avoid common security issues during everyday web development.\u003c\/span\u003e\u003c\/p\u003e\n\u003cp\u003e\u003cspan\u003eThe course combines IT Security fundamentals with security concepts for modern web applications. Topics include authentication, encryption, HTTP security, Content Security Policy, OAuth2, OpenID Connect and vulnerability testing.\u003c\/span\u003e\u003c\/p\u003e\n\u003ch2\u003e\u003cspan\u003eWhat will participants learn?\u003c\/span\u003e\u003c\/h2\u003e\n\u003cp\u003e\u003cspan\u003eAfter the workshop, participants can better identify security risks in web applications and apply appropriate security concepts during development.\u003c\/span\u003e\u003c\/p\u003e\n\u003cp\u003e\u003cspan\u003eParticipants learn how to:\u003c\/span\u003e\u003c\/p\u003e\n\u003cul\u003e\n\u003cli\u003e\u003cspan\u003eUnderstand key IT Security principles such as hashing, encryption and encoding\u003c\/span\u003e\u003c\/li\u003e\n\u003cli\u003e\u003cspan\u003eApply authentication and authorization concepts\u003c\/span\u003e\u003c\/li\u003e\n\u003cli\u003e\u003cspan\u003eUse HTTP security mechanisms and security-relevant HTTP headers\u003c\/span\u003e\u003c\/li\u003e\n\u003cli\u003e\u003cspan\u003eWork with Content Security Policy, JWT, OAuth2 and OpenID Connect\u003c\/span\u003e\u003c\/li\u003e\n\u003cli\u003e\u003cspan\u003eSecure forms, file uploads and REST APIs\u003c\/span\u003e\u003c\/li\u003e\n\u003cli\u003e\u003cspan\u003eRecognize common attacks from the OWASP Top 10\u003c\/span\u003e\u003c\/li\u003e\n\u003cli\u003e\u003cspan\u003eUnderstand XSS, CSRF, injection and credential attacks\u003c\/span\u003e\u003c\/li\u003e\n\u003cli\u003e\u003cspan\u003eApply strategies against Denial-of-Service attacks\u003c\/span\u003e\u003c\/li\u003e\n\u003cli\u003e\u003cspan\u003eUse manual and automated approaches for vulnerability testing\u003c\/span\u003e\u003c\/li\u003e\n\u003cli\u003e\u003cspan\u003eApply static and dynamic analysis to identify vulnerabilities\u003c\/span\u003e\u003c\/li\u003e\n\u003c\/ul\u003e\n\u003ch2\u003e\u003cspan\u003eWho is the course suitable for?\u003c\/span\u003e\u003c\/h2\u003e\n\u003cp\u003e\u003cspan\u003eThe IT Security workshop is aimed at web developers and software developers who implement, design or evaluate web applications in the frontend or backend.\u003c\/span\u003e\u003c\/p\u003e\n\u003cp\u003e\u003cspan\u003eParticipants should have a solid understanding of:\u003c\/span\u003e\u003c\/p\u003e\n\u003cul\u003e\n\u003cli\u003e\u003cspan\u003eHTTP\u003c\/span\u003e\u003c\/li\u003e\n\u003cli\u003e\u003cspan\u003eHTML\u003c\/span\u003e\u003c\/li\u003e\n\u003cli\u003e\u003cspan\u003eBasic JavaScript\u003c\/span\u003e\u003c\/li\u003e\n\u003cli\u003e\u003cspan\u003eIdeally, a dynamic backend programming language\u003c\/span\u003e\u003c\/li\u003e\n\u003c\/ul\u003e\n\u003cp\u003e\u003cspan\u003eThe workshop is designed for experienced developers who want to deepen their knowledge of IT Security and secure web development.\u003c\/span\u003e\u003c\/p\u003e\n\u003ch2\u003e\u003cspan\u003eWhat do participants receive?\u003c\/span\u003e\u003c\/h2\u003e\n\u003cp\u003e\u003cspan\u003eParticipants attend a two-day live online seminar focused on IT Security for web applications.\u003c\/span\u003e\u003c\/p\u003e\n\u003cp\u003e\u003cspan\u003eThey receive:\u003c\/span\u003e\u003c\/p\u003e\n\u003cul\u003e\n\u003cli\u003e\u003cspan\u003eTwo days of live online training\u003c\/span\u003e\u003c\/li\u003e\n\u003cli\u003e\u003cspan\u003eAccess to the seminar via video conference\u003c\/span\u003e\u003c\/li\u003e\n\u003cli\u003e\u003cspan\u003eAccess information sent by email before the workshop\u003c\/span\u003e\u003c\/li\u003e\n\u003cli\u003e\u003cspan\u003eTraining in a small group of 4 to 12 participants\u003c\/span\u003e\u003c\/li\u003e\n\u003cli\u003e\u003cspan\u003ePractical knowledge for securing frontend, backend and API development\u003c\/span\u003e\u003c\/li\u003e\n\u003c\/ul\u003e\n\u003ch2\u003e\u003cspan\u003eWhy this workshop?\u003c\/span\u003e\u003c\/h2\u003e\n\u003cp\u003e\u003cspan\u003eSecurity vulnerabilities often originate during application development. This workshop helps web developers understand these vulnerabilities and consider IT Security directly when designing and implementing web applications.\u003c\/span\u003e\u003c\/p\u003e\n\u003cp\u003e\u003cspan\u003eThe course covers both attack techniques and defensive security concepts. Participants also learn how vulnerability testing can be used to identify security issues in web applications.\u003c\/span\u003e\u003c\/p\u003e\n\u003cdiv id=\"requirements\"\u003e\u003c\/div\u003e\n\u003ch2\u003eAgenda\u003c\/h2\u003e\n\u003ch3\u003eIT Security Basics\u003c\/h3\u003e\n\u003cul\u003e\n\u003cli\u003eSecurity principles\u003c\/li\u003e\n\u003cli\u003e\n\u003cspan\u003eHashing\/\u003c\/span\u003eEncryption\/Encoding\u003c\/li\u003e\n\u003cli\u003eSymmetric \/ asymmetric encryption\u003c\/li\u003e\n\u003cli\u003e\u003cspan\u003eAuthentication \u0026amp; Authorization\u003c\/span\u003e\u003c\/li\u003e\n\u003cli\u003eImportant Algorithms \u0026amp; Principles\u003c\/li\u003e\n\u003c\/ul\u003e\n\u003ch3\u003eSecurity Concepts in Web Applications\u003c\/h3\u003e\n\u003cul\u003e\n\u003cli style=\"font-weight: 400;\"\u003e\u003cspan style=\"font-weight: 400;\"\u003eSame Origin Policy\u003c\/span\u003e\u003c\/li\u003e\n\u003cli style=\"font-weight: 400;\"\u003e\u003cspan style=\"font-weight: 400;\"\u003eCookie Security (Cookie attributes like httpOnly)\u003c\/span\u003e\u003c\/li\u003e\n\u003cli style=\"font-weight: 400;\"\u003e\u003cspan style=\"font-weight: 400;\"\u003eHTTP Security\u003c\/span\u003e\u003c\/li\u003e\n\u003cli style=\"font-weight: 400;\"\u003e\u003cspan style=\"font-weight: 400;\"\u003eProper Use of Security-Relevant HTTP Headers\u003c\/span\u003e\u003c\/li\u003e\n\u003cli style=\"font-weight: 400;\"\u003e\u003cspan style=\"font-weight: 400;\"\u003eContent Security Policy (CSP)\u003c\/span\u003e\u003c\/li\u003e\n\u003cli style=\"font-weight: 400;\"\u003e\u003cspan style=\"font-weight: 400;\"\u003eTransport Encryption\u003c\/span\u003e\u003c\/li\u003e\n\u003cli style=\"font-weight: 400;\"\u003e\u003cspan style=\"font-weight: 400;\"\u003eProper Use of Two-Factor Authentication\u003c\/span\u003e\u003c\/li\u003e\n\u003cli style=\"font-weight: 400;\"\u003e\u003cspan style=\"font-weight: 400;\"\u003eJWT\u003c\/span\u003e\u003c\/li\u003e\n\u003cli style=\"font-weight: 400;\"\u003e\n\u003cspan style=\"font-weight: 400;\"\u003eOAuth2 and OpenID Connect\u003cbr\u003eetc.\u003c\/span\u003e\u003cspan style=\"font-weight: 400;\"\u003e\u003c\/span\u003e\n\u003c\/li\u003e\n\u003c\/ul\u003e\n\u003ch3\u003ePractical Application of Security Concepts\u003c\/h3\u003e\n\u003cul\u003e\n\u003cli\u003e\n\u003cspan\u003eHow to Ensure Data Integrity, Even When\u003c\/span\u003e\n\u003cul\u003e\n\u003cli\u003e\u003cspan\u003eData Runs Over Unsecure Channels\u003c\/span\u003e\u003c\/li\u003e\n\u003cli\u003e\u003cspan\u003eSecuring the Communication Path\u003c\/span\u003e\u003c\/li\u003e\n\u003c\/ul\u003e\n\u003c\/li\u003e\n\u003cli\u003e\n\u003cspan\u003eWhat to Consider\u003c\/span\u003e\n\u003cul\u003e\n\u003cli\u003e\n\u003cspan\u003eWhen Implementing A\u003c\/span\u003e\u003cspan\u003euthentication\u003c\/span\u003e\n\u003c\/li\u003e\n\u003cli\u003e\u003cspan\u003eStoring Passwords Securely\u003c\/span\u003e\u003c\/li\u003e\n\u003cli\u003e\u003cspan\u003eUsing a Web Framework\u003c\/span\u003e\u003c\/li\u003e\n\u003c\/ul\u003e\n\u003c\/li\u003e\n\u003cli\u003e\n\u003cspan\u003eSecure Implementation of\u003c\/span\u003e\n\u003cul\u003e\n\u003cli\u003e\u003cspan\u003eForms and File Uploads\u003c\/span\u003e\u003c\/li\u003e\n\u003cli\u003e\u003cspan\u003eDenial-of-Service Protection Strategies\u003c\/span\u003e\u003c\/li\u003e\n\u003cli\u003e\u003cspan\u003eSecurity Measures for the Frontend and\u003c\/span\u003e\u003c\/li\u003e\n\u003cli\u003e\u003cspan\u003eSecure API Development, Including REST Services\u003c\/span\u003e\u003c\/li\u003e\n\u003c\/ul\u003e\n\u003c\/li\u003e\n\u003c\/ul\u003e\n\u003ch3\u003eAttacks on Web Applications\u003c\/h3\u003e\n\u003cul\u003e\n\u003cli style=\"font-weight: 400;\"\u003e\u003cspan style=\"font-weight: 400;\"\u003eOWASP Top 10\u003c\/span\u003e\u003c\/li\u003e\n\u003cli style=\"font-weight: 400;\"\u003e\u003cspan style=\"font-weight: 400;\"\u003eCredential Attacks\u003c\/span\u003e\u003c\/li\u003e\n\u003cli style=\"font-weight: 400;\"\u003e\u003cspan style=\"font-weight: 400;\"\u003eCross-Site Scripting\u003c\/span\u003e\u003c\/li\u003e\n\u003cli style=\"font-weight: 400;\"\u003e\u003cspan style=\"font-weight: 400;\"\u003eCross Site Request Forgery (CSRF)\u003c\/span\u003e\u003c\/li\u003e\n\u003cli style=\"font-weight: 400;\"\u003e\u003cspan style=\"font-weight: 400;\"\u003eVarious Injection Attacks (e.g., SQL)\u003c\/span\u003e\u003c\/li\u003e\n\u003cli style=\"font-weight: 400;\"\u003e\u003cspan style=\"font-weight: 400;\"\u003eDoS\u003c\/span\u003e\u003c\/li\u003e\n\u003c\/ul\u003e\n\u003ch3\u003eSecuring Web Applications\u003c\/h3\u003e\n\u003cul\u003e\n\u003cli style=\"font-weight: 400;\"\u003e\u003cspan style=\"font-weight: 400;\"\u003eAgainst the Introduced Attack Vectors\u003c\/span\u003e\u003c\/li\u003e\n\u003c\/ul\u003e\n\u003ch3\u003eIntroduction to Vulnerability Testing of a Web Application\u003c\/h3\u003e\n\u003cul\u003e\n\u003cli style=\"font-weight: 400;\"\u003e\u003cspan style=\"font-weight: 400;\"\u003eManual and Automatic Tools\u003c\/span\u003e\u003c\/li\u003e\n\u003cli style=\"font-weight: 400;\"\u003e\u003cspan style=\"font-weight: 400;\"\u003eStatic and Dynamic Analysis for Scanning Vulnerabilities\u003c\/span\u003e\u003c\/li\u003e\n\u003c\/ul\u003e\n\u003cdiv id=\"requirements\"\u003e\u003c\/div\u003e","brand":"Martina Kraus","offers":[{"title":"17.–18. September 2025 \/ 9:00–16:30","offer_id":54080737804556,"sku":"AkaITSecWebDevel-EN","price":1500.0,"currency_code":"EUR","in_stock":false}],"thumbnail_url":"\/\/cdn.shopify.com\/s\/files\/1\/0588\/4333\/2813\/products\/it-sicherheit-fur-webentwickler-virtueller-zwei-tage-workshop-567026.jpg?v=1774865760","url":"https:\/\/karrierewelt.golem.de\/products\/it-security-web-developers-owasp-workshop","provider":"Golem Karrierewelt","version":"1.0","type":"link"}