{"id":820,"date":"2016-01-27T14:30:00","date_gmt":"2016-01-27T14:30:00","guid":{"rendered":"https:\/\/www-new.brucon.org\/2018\/2016\/01\/27\/trainer-spotlight-dawid-czagan-hacking-web-applications\/"},"modified":"2016-01-27T14:30:00","modified_gmt":"2016-01-27T14:30:00","slug":"trainer-spotlight-dawid-czagan-hacking-web-applications","status":"publish","type":"post","link":"https:\/\/archive.brucon.org\/2024\/2016\/01\/27\/trainer-spotlight-dawid-czagan-hacking-web-applications\/","title":{"rendered":"Trainer spotlight &#8211; Dawid Czagan\/Hacking web applications"},"content":{"rendered":"<div style=\"background-color: white;color: #222222;font-family: arial, sans-serif;font-size: 12.8px\">In a &#8220;guest post&#8221; Dawid Czagan explains a little more about what attendees can expect from his training&#8230;<\/div>\n<div style=\"background-color: white;color: #222222;font-family: arial, sans-serif;font-size: 12.8px\"><\/div>\n<div style=\"background-color: white;color: #222222;font-family: arial, sans-serif;font-size: 12.8px\"><\/div>\n<div style=\"background-color: white;color: #222222;font-family: arial, sans-serif;font-size: 12.8px\">\n<div style=\"font-size: 12.8px;line-height: 20.8px\">My hands-on training&nbsp;<span><b>Hacking web applications \u2013 case studies of award-winning bugs in Google, Yahoo, Mozilla and more<\/b><\/span>&nbsp;is unique, because it is based on real, award-winning bugs found in famous companies like Google, Yahoo, Mozilla, Twitter,&#8230;&nbsp;<span><\/span><span>Students&nbsp;will learn how bug hunters think and how to hunt for security bugs effectively.&nbsp;<\/span><span>To be successful in bug hunting, you need to go beyond automated scanners. If you are not afraid of going into detail and doing manual\/semi-automated analysis, then this hands-on training is for you.<\/span><span><\/span><\/div>\n<div style=\"font-size: 12.8px;line-height: 20.8px\">\n<div style=\"font-family: Verdana, Arial, 'Trebuchet MS';line-height: 1.5em;margin: 0.4em 0px 0.5em\"><span>It will be the second edition of this training at BruCON.&nbsp;<\/span><u><span>The first one (BruCON 2015) was sold out.&nbsp;<\/span><\/u><\/p>\n<p>After completing this training, students will have learned about:<\/p><\/div>\n<ul style=\"font-family: Verdana, Arial, 'Trebuchet MS';line-height: 1.5em;list-style-type: square;margin: 0.3em 0px 0px 1.6em;padding: 0px\">\n<li style=\"margin-bottom: 0.1em;margin-left: 0.5em;padding: 0px\">tools\/techniques for effective hacking of web applications<\/li>\n<li style=\"margin-bottom: 0.1em;margin-left: 0.5em;padding: 0px\">non-standard XSS, SQLi, CSRF<\/li>\n<li style=\"margin-bottom: 0.1em;margin-left: 0.5em;padding: 0px\">RCE via serialization\/deserialization<\/li>\n<li style=\"margin-bottom: 0.1em;margin-left: 0.5em;padding: 0px\">bypassing password verification<\/li>\n<li style=\"margin-bottom: 0.1em;margin-left: 0.5em;padding: 0px\">remote cookie tampering<\/li>\n<li style=\"margin-bottom: 0.1em;margin-left: 0.5em;padding: 0px\">tricky user impersonation<\/li>\n<li style=\"margin-bottom: 0.1em;margin-left: 0.5em;padding: 0px\">serious information leaks<\/li>\n<li style=\"margin-bottom: 0.1em;margin-left: 0.5em;padding: 0px\">browser\/environment dependent attacks<\/li>\n<li style=\"margin-bottom: 0.1em;margin-left: 0.5em;padding: 0px\">XXE attack<\/li>\n<li style=\"margin-bottom: 0.1em;margin-left: 0.5em;padding: 0px\">insecure cookie processing<\/li>\n<li style=\"margin-bottom: 0.1em;margin-left: 0.5em;padding: 0px\">session related vulnerabilities<\/li>\n<li style=\"margin-bottom: 0.1em;margin-left: 0.5em;padding: 0px\">mixed content vulnerability<\/li>\n<li style=\"margin-bottom: 0.1em;margin-left: 0.5em;padding: 0px\">SSL strip attack<\/li>\n<li style=\"margin-bottom: 0.1em;margin-left: 0.5em;padding: 0px\">path traversal<\/li>\n<li style=\"margin-bottom: 0.1em;margin-left: 0.5em;padding: 0px\">response splitting<\/li>\n<li style=\"margin-bottom: 0.1em;margin-left: 0.5em;padding: 0px\">bypassing authorization<\/li>\n<li style=\"margin-bottom: 0.1em;margin-left: 0.5em;padding: 0px\">file upload vulnerabilities<\/li>\n<li style=\"margin-bottom: 0.1em;margin-left: 0.5em;padding: 0px\">caching problems<\/li>\n<li style=\"margin-bottom: 0.1em;margin-left: 0.5em;padding: 0px\">clickjacking attacks<\/li>\n<li style=\"margin-bottom: 0.1em;margin-left: 0.5em;padding: 0px\">logical flaws<\/li>\n<li style=\"margin-bottom: 0.1em;margin-left: 0.5em;padding: 0px\">and more\u2026<\/li>\n<\/ul>\n<\/div>\n<p><br style=\"font-size: 12.8px\" \/><span>This hands-on training was attended by security specialists from big companies like Oracle, Adobe, ESET, ING, Red Hat, Trend Micro, Philips, government sector and it was very well-received (recommendations here:&nbsp;<a href=\"https:\/\/silesiasecuritylab.com\/services\/training\/#opinions\" target=\"_blank\">https:\/\/silesiasecuritylab.com\/services\/training\/#opinions<\/a>&nbsp;).<\/span><span><\/p>\n<p>Students will be handed in a VMware image with a specially prepared testing environment to play with the bugs. What&#8217;s more, this environment is self-contained and when the training is over, students can take it home (after signing a non-disclosure agreement) to hack again at their own pace.<\/span><\/div>\n<div style=\"background-color: white;color: #222222;font-family: arial, sans-serif;font-size: 12.8px\">\n<ul style=\"font-family: Verdana, Arial, 'Trebuchet MS';line-height: 1.5em;list-style-type: square;margin: 0.3em 0px 0px 1.6em;padding: 0px\"><\/ul>\n<\/div>\n","protected":false},"excerpt":{"rendered":"<p>In a &#8220;guest post&#8221; Dawid Czagan explains a little more about what attendees can expect from his training&#8230; My hands-on training&nbsp;Hacking web applications \u2013 case studies of award-winning bugs in Google, Yahoo, Mozilla and more&nbsp;is unique, because it is based on real, award-winning bugs found in famous companies like Google, Yahoo, Mozilla, Twitter,&#8230;&nbsp;Students&nbsp;will learn how bug hunters think and how to hunt for security bugs effectively.&nbsp;To be successful in bug hunting, you need to go&#8230;<\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[15,17,19,5],"tags":[],"class_list":["post-820","post","type-post","status-publish","format-standard","category-15","category-brucon","category-spring","category-training"],"menu_order":0,"_links":{"self":[{"href":"https:\/\/archive.brucon.org\/2024\/wp-json\/wp\/v2\/posts\/820","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/archive.brucon.org\/2024\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/archive.brucon.org\/2024\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/archive.brucon.org\/2024\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/archive.brucon.org\/2024\/wp-json\/wp\/v2\/comments?post=820"}],"version-history":[{"count":0,"href":"https:\/\/archive.brucon.org\/2024\/wp-json\/wp\/v2\/posts\/820\/revisions"}],"wp:attachment":[{"href":"https:\/\/archive.brucon.org\/2024\/wp-json\/wp\/v2\/media?parent=820"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/archive.brucon.org\/2024\/wp-json\/wp\/v2\/categories?post=820"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/archive.brucon.org\/2024\/wp-json\/wp\/v2\/tags?post=820"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}