Secure Coding and Modern Application Security Workshop
Controlled attack labs, secure development workflows and remediation evidence
Why this course
This two-day workshop combines application-security foundations with selected attack, remediation and retesting exercises. Web, API, mobile and data-processing examples use relevant portions of .NET, Node.js, Java, Flutter, Go and SAS without attempting separate technology deep dives.
Short demonstrations and guided discussions introduce secure development, dependency security, CI/CD controls and AI-assisted review. Participants complete selected exercises and a bounded final investigation. PCI DSS v4.0.1 Requirement 6 and OWASP guidance provide context; the workshop does not certify compliance or constitute a complete security assessment.
Learning outcomes
- Explain HTTP, authentication, authorisation and application trust boundaries.
- Map a supplied application and investigate selected injection, data-handling, workflow and access-control weaknesses.
- Apply selected defensive corrections for passwords, secrets, browser security and object-level authorisation.
- Explain the roles and limits of code review, SAST, DAST and software composition analysis.
- Relate workshop findings to secure-development and current OWASP risk categories.
- Evaluate an AI-generated fix using human code review and independent tests.
- Document root cause, remediation, security retesting and legitimate-functionality regression results.
Prerequisites
- Basic software-development or application-support experience and basic API/database knowledge.
- Ability to read one relevant language, such as C#, JavaScript, Java, Dart, Go or SAS.
- Basic command-line skills; a suitable laptop and authorised administrator access to the supplied lab environment.
- No previous penetration-testing experience is required; HTTP and web concepts are introduced briefly.
10 modules
01Day 1 — Foundations and lab setup5 topics
- Threats, vulnerabilities, attack vectors, trust boundaries, client-versus-server enforcement and regression testing.
- HTTP methods, routes, parameters, headers, cookies, bodies, JSON, tokens and authentication versus authorisation.
- Supplied vulnerable application, local services, test users and data, reset/recovery procedures and application logs.
- Browser tools, proxy, API client, command-line requests and code editor; trace a normal request before modifying it.
- Map enterprise backends, Flutter client-to-API interactions and SAS data-processing boundaries.
02Day 1 — Injection and secure input handling4 topics
- SQL injection: inspect unsafe dynamic queries, apply parameterised operations and least-privilege access, then retest.
- Command injection: distinguish shell interpretation from argument injection; avoid unnecessary shells and validate permitted operations.
- LDAP, XPath and template-injection demonstrations, with context-appropriate query APIs and escaping.
- Type, length, range and allow-list validation; negative, boundary and legitimate-input regression tests.
03Day 1 — Data, object binding and files5 topics
- Malformed and extreme input, server-side schema validation and safe error handling.
- Mass assignment and over-posting: inspect unexpected or privileged properties; use DTOs, explicit mapping and property-level authorisation.
- Unsafe deserialisation, polymorphic types, restricted formats and safer replacement patterns.
- File upload and path traversal: generated filenames, content and size validation, secure storage and temporary-file handling.
- Retest manipulated requests while confirming legitimate updates and file operations.
04Day 1 — Business logic and API abuse5 topics
- Map transaction states, approvals, trust assumptions and server-side enforcement points.
- Investigate skipped or reordered steps, replay, duplicate submissions and partial-completion abuse.
- Enforce workflow state, replay and duplicate-request protections appropriate to the transaction.
- Test price, quantity, discount, negative/extreme values and hidden fields; calculate trusted values on the server.
- Treat API and mobile clients as untrusted inputs; retest business rules and legitimate workflows.
05Day 2 — Authentication, sessions and access control5 topics
- Default credentials, enumeration, password resets, MFA weaknesses, lockout and rate-limit trade-offs.
- Session fixation, token predictability/reuse, logout, rotation, cookie attributes and token validation.
- Horizontal access: ownership and tenant boundaries; vertical access: restricted functions and administrator permissions.
- IDOR/BOLA: evaluate read, update and delete permissions for each object; identifiers do not replace authorisation.
- Centralised deny-by-default policies and role matrices; retest owners, other users, tenants and privileged roles.
06Day 2 — Browser and client-side security5 topics
- Reflected, stored and DOM XSS: output contexts, encoding, sanitisation, safe DOM APIs and framework controls.
- Use Content Security Policy as defence in depth; retest malicious input and legitimate rendering.
- CSRF in cookie-authenticated state changes: request tokens and origin checks, with SameSite as additional protection.
- Re-authentication for sensitive actions; verify rejected forged requests and successful legitimate requests.
- Browser and Flutter storage, tokens, source maps and exposed secrets; enforce controls on the server.
07Day 2 — Passwords, secrets and cryptography5 topics
- Password hashing versus reversible storage; salts, appropriate work factors and maintained libraries.
- Find secrets in source, configuration, logs and build artifacts; use secret stores, access controls, secure injection and rotation.
- TLS, certificate/hostname verification, trust stores and insecure fallback.
- Token unpredictability, secure randomness, signing and integrity checks.
- Choose suitable algorithms and libraries, separate keys and fail securely; inspect storage and retest functionality.
08Day 2 — Secure development and modern application security1 topics
Standards and review
- PCI DSS Requirement 6 context: secure development, vulnerability management, security testing, remediation and evidence.
- Current OWASP Top 10:2025 risk families, including supply-chain failures and exceptional-condition handling; discuss relevant SSRF and integrity examples.
- Security-focused code and pull-request review: input, authentication, authorisation, cryptography, secrets and documented findings.
Tools, dependencies and delivery
- SAST analyses code; DAST exercises running applications; SCA examines dependencies. Discuss limitations, false positives and validation.
- Demonstrate one selected tool finding, verify it, remediate and rescan or retest.
- Direct/transitive dependencies, trusted sources, package integrity, version management, SBOM concepts and patching.
- CI/CD credentials, repository and build-log exposure, secret injection and scanning.
- Security requirements, threat identification, design, review, testing, triage, gates, change approval and release controls.
- An illustrative pipeline combines code review, SAST/SCA, builds, test-environment DAST, remediation and approval; adapt order and gates to the workflow.
AI-assisted review
- Use an approved coding assistant for a bounded analysis or remediation demonstration.
- Protect sensitive code and secrets; account for incorrect suggestions, governance and acceptable-use controls.
- Human review and independent retesting determine whether to accept or reject a proposed fix.
09Day 2 — Remediation and retesting evidence4 topics
- Triage reproduction reliability, preconditions, exploitability, exposure, business impact and root cause.
- Select validation, parameterisation, output encoding, explicit binding, authorisation, cryptographic APIs, safe errors or least privilege as appropriate.
- Replay original tests; add negative, boundary, alternate-input, role, API and functional regression checks.
- Document the finding, root cause, correction, retest results, evidence and closure decision.
10Day 2 — Final guided investigation4 topics
- Choose selected weaknesses in the controlled application rather than attempting every vulnerability class.
- Review endpoints and trust boundaries; investigate injection, object binding, workflow, XSS, IDOR/BOLA, access control or secret exposure.
- Explain root cause, apply or review a correction, and confirm expected functionality.
- Replay the security test and relevant regressions; report evidence and applicable PCI or OWASP relationships without asserting overall compliance.
A programme built around your team.
Share your training goals and requirements.