OWASP & Security Testing at DVWA
Application and infrastructure security — a workshop for technical teams.
Ideal for teams that…
Application and infrastructure security — a workshop for technical teams.
To understand the mission and key projects of OWASP, including the OWASP Top 10 list
To install and configure a testing environment (Kali Linux, DVWA)
To perform penetration testing of web applications in low, medium, and high modes
To detect and exploit common vulnerabilities: SQL Injection, XSS, CSRF, LFI/RFI, Path Traversal, Command Injection
To use basic pentesting tools (Burp Suite, sqlmap, Hydra)
To apply best practices for securing web applications and reducing risk
What we actually do
Day 1
- · Module 1: Introduction to Web Application Security What OWASP is – mission, goals, and projects Overview of the OWASP Top 10 (latest version) The importance of security in the application lifecycle
- · Module 2: Preparing the Environment Installing Kali Linux (VirtualBox / VMware) Updating and configuring the system Installing and configuring DVWA (Damn Vulnerable Web Application) Running Apache and MySQL services Accessing DVWA in the browser
- · Module 3: Basics of Testing Introduction to penetration testing methodology Security levels in DVWA (low, medium, high) Working in a controlled laboratory environment
Day 2
- · Module 4: Key Web Application Vulnerabilities Path Traversal – accessing files outside the application directory Local File Inclusion (LFI) Remote File Inclusion (RFI) SQL Injection – manipulating database queries Command Injection – executing system commands Cross-Site Scripting (XSS) Cookie manipulation and session hijacking Brute-force attacks on application login Cross-Site Request Forgery (CSRF) File upload vulnerabilities
- · Module 5: Tools in Security Testing Kali Linux tools: Burp Suite sqlmap Hydra Browser and developer tools HTTP/HTTPS traffic analysis
- · Module 6: Summary How to secure web applications Best practices in secure coding Further learning resources: OWASP Cheat Sheets DVWA documentation
From brief to retro in 30 days.
Brief & diagnosis
A call with the team lead + a short survey for participants. We define goals, gap and context.
Program customization
We adapt modules, case studies and code examples to your stack. Approval in 5 days.
Workshop
Trainer-led sessions, hands-on, code review. Mentor available between sessions too.
Retro + report
Outcome report for the team and lead. 30 days of consulting included.
Send a brief. We'll reply within 1 day.
After a short brief we'll prepare a program and a quote. No obligations — it's just a starting point.
Thank you!
We'll get back to you within 1 business day.
Other programs for teams
See all →AWS Cloud Security Training
Application and infrastructure security — a workshop for technical teams.
Azure Cloud Security Training
Application and infrastructure security — a workshop for technical teams.
Container security management
Application and infrastructure security — a workshop for technical teams.