November 18 and 19, 2010: ITACS-Course "Web 2.0 - Web Application Security: Advanced"

Learning targets: The participants expand their knowledge from LAB-WAB in respect of Web 2.0/AJAX and Web Application Firewall. They comprehend additional risks with Web 2.0 applications, the significance of the Same Origin Policy and also Cross Domain (XDR) topics and Mash-Ups.
Event date: November 18, 2010 9:15 AM to November 19, 2010 5:15 PM

Please note: This course is hold in German. For courses in English, please contact Compass Security directly: Telefon +41 55 214 41 60 or team@csnc.ch

The following course is offered in co-operation with ISACA and the ITACS Training AG in Zurich. Further information is available for you on www.itacs.ch where you may also enrol for this course.

Target group:
- Security Officers
- Web developers
- Continuation of the course LAB-WAB

Requirements:
- Familiarity with the Windows command line
- Knowledge of the HTTP protocol
- JavaScript, GET/POST, XML are known terms
- Attendance of the course LAB-WAB

Contents:
- Repetition OWASP TOP 10
- Introduction Web 2.0
- XML attacks
- XPath injection
- Ajax, XMLHttpRequest and Same Origin Policy (Bypass)
- Google Web Toolkit / DWR Framework
- Web Application Firewall (Airlock, SES, NevisWeb, OpenSource, …)
- Discussion on defence measures / priorities

Scope:
The course is focussed on the Web layer. Nessus, Nmap and vulnerability scanning are not part of this course (these topics are dealt with in the course LAP-NP). The course is the continuation of the basic course LAB-WAB.


Event location:  ITACS Training AG
Stampfenbachstrasse 40
8006 Zürich
Phone: +41 (0)44 444 11 01
Fax: +41 (0)44 444 11 02
Email: kurse@itacs.ch
Link: Location

Further links:

News

HTML5 Web Security
12/7/11 - HTML5 Security Research Report

Review BlackHat / Defcon 2011
11/8/11 - This year, as every year, two security analysts of Compass Security AG participated in the BlackHat and Defcon in Las Vegas.

Oracle RDC Onsite XSS Vulnerability
10/18/11 - Compass Security has found a vulnerability in ORACLE RDC ONSITE.

Course Schedule - New iPhone & iPad Hands-On course
10/6/11 - The new iPhone & iPad Compass course will be held in Switzerland for the first time

it-sa 2011: Compass Live-Hacking at IT-SA 2011 in Nürnberg
9/29/11 - Meet Compass at IT-SA Messestand in Halle 12, Stand 226. We will present Live-Hackign with newest iPhone and Mobile Devices.