Training

OWASP Top 10 Advanced: finding vulnerabilities yourself

Your team knows the OWASP Top 10 and now needs to find vulnerabilities in web applications itself. The workshop goes deeper into testing tools and methods from penetration testing and practises finding vulnerabilities in OWASP Juice Shop.

Two mornings as an interactive webinar. Builds on the basic module, but can also be booked without it given suitable prior knowledge.

Free of charge and without obligation.

  • OWASP Corporate Member · Silver Sponsor
  • Trainers are penetration testers
Two secuvera experts examining a navigation instrument together
OWASP Top 10 Advanced: learn to find vulnerabilities yourself.

Your situation

Your team knows the OWASP Top 10 – and now needs to find vulnerabilities itself?

The basics are in place: your team has got to know the OWASP Top 10, perhaps in our basic module. In day-to-day work, it then becomes clear that terms alone are not enough. Developers want to check for themselves during a code review or before a release whether an application is vulnerable – with the same tools that penetration testers use.

The Advanced module therefore focuses on hands-on practice. After a short refresher, participants search for vulnerabilities themselves in OWASP Juice Shop, a deliberately vulnerable web application. The trainers come from our pentest team and show how they work in a penetration test.

The module is aimed at developers and DevOps, technically experienced product owners, product and project owners, and IT administration with knowledge of web technologies.

Services & results

Refresh, get to know the tools, search in Juice Shop yourself

Your team finds vulnerabilities in web applications itself: after a refresher on the OWASP Top 10, penetration testers show their tools and methods, such as Burp in line with the OWASP Web Security Testing Guide, and the participants then search for and confirm vulnerabilities in OWASP Juice Shop. For development, DevOps, product owners and IT administration with knowledge of web technologies. The training is available in German or English.

The first part refreshes the content of the basic module, then the in-depth part begins: testing tools from penetration testing and Hunt the Bug in OWASP Juice Shop. Two mornings, each from 9:00 to 12:30.

Refresher on the basics

A compact run-through of the topics of the basic module, so that all participants start the exercises at the same level.

  • OWASP – overview and selected projects
  • Examples from public reporting
  • Brief overview of the OWASP Top 10, including SQL injection, XXE and cross-site scripting

Testing tools and methods from penetration testing

The trainers show the tools and methods we use to test web applications in a penetration test, e.g. Burp – in line with the OWASP Web Security Testing Guide and the technically testable parts of the OWASP Top 10. The focus is on how to find and confirm a vulnerability, not just what it is called.

Hunt the Bug in OWASP Juice Shop

The trainers set challenges in OWASP Juice Shop, each with a fixed time frame. Participants solve them together with the trainers or – by arrangement – independently in small groups. The aim is for the team to exchange ideas with each other along the way.

Debrief and countermeasures

Each challenge is debriefed together: how the vulnerability could be found, why it was exploitable and which countermeasures would have prevented it. The trainers record questions from the session in show notes with references.

Result

Your team has found vulnerabilities in a web application itself and can justify suitable countermeasures.

Our expertise

In the Advanced module, penetration testers show how they work themselves. Trainers include Tobias Glemser, BSI-certified penetration tester and technical lead for penetration testing at secuvera. He has published security advisories on vulnerabilities he found in web applications and IoT devices and speaks about the practice of web application pentests, for example at DevSecCon Germany with “Application Penetration Testing – Do’s and Dont’s”.

The methods in the workshop are the same ones secuvera has used for penetration tests since 2000: we test web applications in line with the OWASP Web Security Testing Guide and the technically testable parts of the OWASP Top 10. Tobias Glemser also leads the OWASP German Chapter; secuvera is an OWASP Corporate Member.

Getting started

Format and schedule

Two mornings, remote

From 9:00 to 12:30 on each of two days, as an interactive webinar via Zoom – or via your platform, such as Webex or Teams. On site on request; in that case you provide the room and presentation equipment.

Hunt the Bug: interactive or in small groups

You solve the tasks either together with the trainers or independently in small groups. For small groups, we can provide virtual machines that run in the browser on request; the video platform must then allow breakout rooms – our Zoom solution does.

Up to 15 participants

You decide the number. For didactic reasons, we recommend up to 15 participants; with more than 20, the results suffer.

Interval after the basic module

If you book both modules, allow at least six, preferably twelve months between the basic and the Advanced module.

Plan OWASP training
Several hands working with compass and dividers between sticky notes on a map
Hands-on practice: spot vulnerabilities before you set course for release.

secuvera is the training provider

The training is offered by secuvera and teaches OWASP methods. It is not a training course of the OWASP® Foundation.

Questions about the Advanced workshop

Do we need the basic module first?

Not necessarily – depending on your level of knowledge, it also works without. If you book both modules, allow at least six, preferably twelve months between the basic and the Advanced module.

How is the training structured?

Over two mornings from 9:00 to 12:30 as an interactive webinar: theory, joint technical demonstrations, polls and discussion. 95% of participants prefer this format to a full training day. Zoom is the standard; Webex, Teams or your own platform also work, and on request the training takes place on site.

How many people can take part?

You decide. We recommend up to 15 participants; with more than 20, the results suffer. The price applies per session, regardless of the number of participants.

Is the training adapted to our applications?

No. The modules are standard training courses that we continue to develop across all sessions. If you wish, send us a list of your internal requirements in advance, such as development guidelines – the titles are sufficient.

Are there training materials?

No handouts. The slides are structured so that the content can be followed up later; in addition, there are show notes with the questions from your session and references. Certificates of attendance are available on request.

How can we support you with OWASP Top 10 Advanced?