Hyppää sisältöön

Koulutus

Web Security Fundamentals

Learn how to identify, prevent, and defend against the cyber threats and vulnerabilities targeting modern web applications today.

Ajankohta

8.–9.12.2026

remote

Etäkoulutus, Etäkoulutus

Ajankohta

8.–9.12.2026

remote

Etäkoulutus, Etäkoulutus

From Vulnerable to Secure.

Today’s internet is a very rough place, with robots, spies, states, hackers, and other evil entities constantly roaming around the web looking for vulnerable web applications to attack. Because of this, it is very important that every developer has the necessary skills to protect their applications. 

In this hands-on course, you will learn the fundamentals of how the web works, how to protect your applications, and how attacks are performed. It goes beyond the OWASP TOP-10 and gives you many concrete examples of how to fail and how to protect your applications. 

Target Audience

This course is designed for developers, testers, and architects who want to build and maintain secure applications, regardless of platform or industry. It’s well suited to organizations handling sensitive data or user information, including software companies, finance, healthcare, e-commerce, and the public sector. The content is platform-independent, applying equally to .NET, Java, PHP, and other technology stacks. 

Additional information

  • Basic web development experience, including HTML, CSS, and JavaScript 
  • A general understanding of how web applications work 
  • No prior security experience required, suitable for both beginners and experienced developers 

Osta liput

LEARN

practical techniques to defend against XSS, CSRF, injection attacks, and other common web vulnerabilities.

GAIN

hands-on experience attacking and defending real applications, not just theory.

GO BEYOND

the OWASP Top 10 with concrete, up-to-date examples of how attacks happen and how to prevent them.

BUILD

platform-independent skills that apply across .NET, Java, PHP, and other technology stacks.

    • Päivä 1

      Introduction to Web Security

      add_2 close
      • Why do we need web security? 
      • Protecting your users and their data 
      • Social Engineering 
      • Goals and focus 
      • Trust boundaries and the basic principles of web security 

      Break

      Character Encoding and HTTPS

      add_2 close
      • Character sets, Unicode and the problem with characters 
      • Encodings: UTF-8 and UTF-16 
      • The problem with HTTP and the fundamentals of HTTPS 
      • Protocols, ciphers and moving from HTTP to HTTPS 
      • HTTP Strict Transport Security (HSTS) 

      Lunch Break

      Certificates and Secure Connections

      add_2 close
      • Certificate Authorities (CAs) and certificate trust 
      • Certificate lifetime and renewal 
      • Certificate pinning 
      • Mutual TLS (mTLS) 
      • Managing certificates securely 

      Coffee Break

      Cross-Site Scripting (XSS)

      add_2 close
      • Reflected, stored and self-XSS 
      • Data sanitization and safe handling of user input 
      • Mutation XSS 
      • Preventing and mitigating XSS vulnerabilities 

      Content Security Policy (CSP)

      add_2 close
      • Policies and directives 
      • Creating effective CSP policies 
      • CSP reporting and production use 
      • Strict CSP 

      See you tomorrow! The first training day ends

    • Päivä 2

      CSRF, Cookies and Browser Security

      add_2 close
      • Understanding cookies and Cross-Site Request Forgery (CSRF) 
      • Protecting applications against CSRF 
      • Securing cookies with HttpOnly and Secure 
      • Prefixed cookie names, CHIPS and partitioned cookies 
      • SameSite cookies: Strict, Lax and None 

      Break

      Securing Dependencies and Injection Attacks

      add_2 close
      • Typosquatting and source control attacks 
      • Build server security and Subresource Integrity 
      • SQL injection and blind SQL injection 
      • Code and XML injection attacks 
      • File inclusion attacks 

      Lunch Break

      Securing the Session and Authentication

      add_2 close
      • Detecting stolen cookies 
      • Fingerprinting and Cookie Confusion 
      • Multi-Factor Authentication (MFA) 
      • Mobile authenticators 
      • Protecting user sessions and authentication flows 

      Coffee Break

      Denial-of-Service and Building Secure Websites

      add_2 close
      • Denial-of-Service attacks against applications 
      • Attacking XML and regular expressions 
      • Trust boundaries and Zero Trust 
      • Hack yourself: testing your own security 
      • Honeypots and defensive security techniques 

      Summary and Key Takeaways

      add_2 close
      • Review of the most important web security principles 
      • Connecting the different security controls 
      • Practical considerations for building secure web applications 

      Thank you! The training ends

    Tore Nestenius

    .NET Architect & Technical Trainer | Microsoft MVP | OpenID Connect, Identity, and Security Expert

    Tore Nestenius