· The unique security aspects and challenges of web applications
· Application layer logical vulnerabilities
· Application layer DoS and DDoS
· Encryption and hashing
· SSL
· HTTP basic and digest authentication
· Certificate based authentication
· Application layer authentication
· Web session management mechanisms
· Session hijacking
· Cookie poisoning
· Direct object reference vulnerability and mitigation
· Input validation methodology
· Evasion techniques
· SQL injection attack description and examples
· SQL injection evasion techniques
· Command (OS) injection
· LDAP Injection
· Buffer overflow
· Reflected XSS
· Stored XSS
· DOM based XSS
· XSS evasion techniques
· XSS mitigation countermeasures
· CSRF (XSRF) attack description
· ISRF attack description
· CSRF/ISRF mitigation countermeasures
· OpenID
· OAuth
· SAML
· XCAML
· Web application single sign on (SSO) and OpenID
· Security of AJAX based web applications
· Summary
· Q&A
· Evaluation