HTTP Security Headers
o Content-Security-Policy (CSP)
o Strict-Transport-Security Header (HSTS)
o X-Content-Type-Options
o X-Frame-Options
o Referrer-Policy
Introduction to Web Application Security
o Vulnerability Stack
o Defense in depth
Web Application Penetration Testing Methodology
o OWASP (Open Web Application Security Project)
o OSSTMM (Open Source Security Testing Methodology Manual)
o PTF (Penetration Testing Framework)
o ISSAF (Information Systems Security Assessment Framework)
o PCI DSS (Payment Card Industry Data Security Standard)
o Types of Web Penetration Testing
o Internal Penetration Testing
o External Penetration Testing
o Web Application Penetration Testing Tools
o Zed Attack Proxy (ZAP)
o Wfuzz
o Wapiti
o W3af
o SQLMap
Web Application Penetration Testing Checklist
o Penetration Testing Certifications
o OSWE (Offensive Security Web Expert)
o GWAPT (GIAC Web Application Penetration Tester)
o CWAPT (Certified Web App Penetration Tester)
o eWPT (elearnSecurity Web Application Penetration Tester) |