To wersja testowa nowego serwisu infoShare Academy — wyświetlane treści i oferta nie są wiążące ani kompletne

Security

OWASP & Security Testing at DVWA

Application and infrastructure security — a workshop for technical teams.

Duration
16h · 2 days
Who it's for

Ideal for teams that…

1 Developers who want to learn the most common security mistakes in applications
2 Software testers entering the field of security testing
3 System administrators and DevOps teams interested in strengthening web application security
4 People starting a career in cybersecurity
Outcomes after the program

Application and infrastructure security — a workshop for technical teams.

To understand the mission and key projects of OWASP, including the OWASP Top 10 list

To install and configure a testing environment (Kali Linux, DVWA)

To perform penetration testing of web applications in low, medium, and high modes

To detect and exploit common vulnerabilities: SQL Injection, XSS, CSRF, LFI/RFI, Path Traversal, Command Injection

To use basic pentesting tools (Burp Suite, sqlmap, Hydra)

To apply best practices for securing web applications and reducing risk

Program · 2 modules

What we actually do

Day 1

M01
Day 1
  • · Module 1: Introduction to Web Application Security What OWASP is – mission, goals, and projects Overview of the OWASP Top 10 (latest version) The importance of security in the application lifecycle
  • · Module 2: Preparing the Environment Installing Kali Linux (VirtualBox / VMware) Updating and configuring the system Installing and configuring DVWA (Damn Vulnerable Web Application) Running Apache and MySQL services Accessing DVWA in the browser
  • · Module 3: Basics of Testing Introduction to penetration testing methodology Security levels in DVWA (low, medium, high) Working in a controlled laboratory environment

Day 2

M02
Day 2
  • · Module 4: Key Web Application Vulnerabilities Path Traversal – accessing files outside the application directory Local File Inclusion (LFI) Remote File Inclusion (RFI) SQL Injection – manipulating database queries Command Injection – executing system commands Cross-Site Scripting (XSS) Cookie manipulation and session hijacking Brute-force attacks on application login Cross-Site Request Forgery (CSRF) File upload vulnerabilities
  • · Module 5: Tools in Security Testing Kali Linux tools: Burp Suite sqlmap Hydra Browser and developer tools HTTP/HTTPS traffic analysis
  • · Module 6: Summary How to secure web applications Best practices in secure coding Further learning resources: OWASP Cheat Sheets DVWA documentation
Every module is adapted to your stack and context. The above is a starting point — not a fixed agenda.
How we work

From brief to retro in 30 days.

01

Brief & diagnosis

A call with the team lead + a short survey for participants. We define goals, gap and context.

02

Program customization

We adapt modules, case studies and code examples to your stack. Approval in 5 days.

03

Workshop

Trainer-led sessions, hands-on, code review. Mentor available between sessions too.

04

Retro + report

Outcome report for the team and lead. 30 days of consulting included.

Inquiry

Send a brief. We'll reply within 1 day.

After a short brief we'll prepare a program and a quote. No obligations — it's just a starting point.

Quote within 48h of the brief
First session within 30 days
Pilot before the full decision
VAT invoice, payment in instalments possible

How we handle your data

We process your business data (name, work e-mail, phone number, company, job title) in order to handle your corporate training inquiry and prepare an offer. The data controller is infoShare Academy Sp. z o.o., Al. Grunwaldzka 472B, 80-309 Gdańsk. Providing the data is voluntary but necessary to receive a response. You have the right to access, rectify, erase or restrict the processing of your data and to object to it. Full information is available in our data processing notice.

Optional marketing consents

The controller of your personal data is infoShare Academy sp. z o.o. The rules for processing personal data are set out in the Privacy Policy and the Data Processing Notice.