CERN Computing Seminar

Web security / penetration testing: introduction (1/2)

by Sebastian Lopienski (CERN)

Europe/Zurich
Webinar (CERN)

Webinar

CERN

Description

COMPUTER SECURITY SERIES - @CERN

In order to protect computers and networks from malicious attacks, we need to find and fix any vulnerabilities before they are identified and exploited by the bad guys (Black Hats). One of the ways to achieve it is to do penetration (security) testing. To do this efficiently, the good guys (White Hats) have to think and act as the bad guys - but with the ultimate goal of securing the target rather than abusing it.

In this and the following seminar, you will learn to think and act like a White Hat penetration tester. We will focus on web applications, as these are the most common targets in any organisation.

The introduction to web security penetration testing will cover ethics and rules, remind how HTTP protocol works, demonstrate briefly some web applications server-side vulnerabilities, and demonstrate how client-side tools can help in penetrating testing.

Hands-on exercises

In order to access the hands-on exercises, please subscribe to whitehat-exercise-access egroup (available for CERN accounts owners only).

About the speaker

Sebastian Lopienski serves as CERN's deputy Computer Security Officer. He is also the director of the CERN School of Computing.

From the same series
2
Organised by

Stefan Lüders/CERN and Vincenzo Ciaschini‎/CNAF

Logistics: Miguel Angel Marquina - IT Department
CERN Computing Seminars and Colloquia