Invalid quantity. Please enter a quantity of 1 or more.
The quantity you chose exceeds the quantity available.
Please enter your name.
Please enter an email address.
Please enter a valid email address.
Please enter your message or comments.
Please enter the code as shown on the image.
Please select the date you would like to attend.
Please enter an email address.
Please enter a valid email address in the To: field.
Please enter a subject for your message.
Please enter a message.
You can only send this invitations to 10 email addresses at a time.
$$$$ is not a properly formatted color. Please use the format #RRGGBB for all colors.
Please limit your message to $$$$ characters. There are currently ££££.
$$$$ is not a valid email address.
Please enter a promotional code.
N/A
Sold Out
Pending
You have exceeded the time limit and your reservation has been released.
The purpose of this time limit is to ensure that registration is available to as many people as possible. We apologize for the inconvenience.
This is option is not available anymore. Please choose a different option.
Please read and accept the waiver.
All fields marked with * are required.
Please double check your email address. The email address format does not appear valid.
$$$$ requires a number between ££££ and §§§§
US Zipcodes need to be 5 digits.
Please double check your website URL.
All fields marked with * are required.
Your credit card expiration date is in the past.
Your credit card CSC needs to be 4 digits.
Please confirm your order:
$$$$
You have selected to Pay by Check.
Click OK to confirm your order.
Please confirm your order:
$$$$
You have selected to Pay at the Door.
Click OK to confirm your order.
Please confirm your order:
$$$$
You have selected to Pay upon Receiving an Invoice.
Click OK to confirm your order.
Your credit card CSC needs to be 3 digits.
Your billing zip code needs to be 5 digits.
There was a problem saving your address.
There was a problem saving your credit card info.
There was a problem saving your personal information.
Please select the date you would like to attend.
McAfee Secure sites help keep you safe from identity theft, credit card fraud, spyware, spam, viruses and online scams.
Copying Prohibited by Law - McAfee Secure is a Trademark of McAfee, Inc.
Unknown card type.
No card number provided.
Credit card number is in invalid format.
Wrong card type or credit card number is invalid.
Credit card number has an inappropriate number of digits.
Please enter numbers here.
Please enter an integer value.
Numbers must be less or equal to $$$$
All the required fields have not been filled out. Click OK to proceed without all the required information, or click Cancel to finish entering the missing data.
Sorry, invalid event registration form.
Sorry, invalid event or database error.
Sorry, quantity must be a positive integer.
Sorry, you did not select a valid ticket.
Sorry, invalid event organizer email address.
Your order was canceled.
Thank You. Your order has been successfully completed. Your name and email address have been added to the list of event attendees.
Sorry, that option is sold out.
Sorry, that option is no longer available.
Sorry, there are only tickets of that type still available.
Sorry, you entered an invalid quantity. Please enter a quantity of 1 or more next to the type or types of tickets you would like to purchase.
Sorry, you did not select any tickets to purchase. Please enter a quantity of 1 or more next to the type or types of tickets you would like to purchase.
Sorry, there are no tickets left for this event.
The tickets, ticket quantity or date and time you've requested are no longer available, due to previous sales. Please choose a different date, time or number of tickets and place your order again.
Sorry, one or more of the tickets you requested are no longer available for purchase.
Sorry, you need to select the date you want to attend.
Sorry, the promotional code you entered is not valid yet.
Sorry, the promotional code you entered has expired.
Sorry, the promotional code you entered is not valid.
Your session has expired. Try ordering again.
Sorry, your requested ticket quantity exceeds the number provided by your promotional code.
Sorry, the tickets you are trying to order are not currently available.
Sorry, the payment type chosen is invalid for this event.
Sorry, there is only 1 ticket left for this event.
Sorry, there are only tickets left for this event.
We're sorry, this invitation is invalid.
We're sorry, this invitation has already been used.
We're sorry, you already have an order being processed for this event. Please wait a few minutes and try again.
We're sorry, there is a problem with your invitation. Please try again.
Invalid quantity of tickets selected.
Invalid donation amount.
Sorry, the promotional code you entered has been claimed.
Sorry, the payment type chosen is invalid for this event.
Sorry, your billing address was not saved properly, please try again.
Sorry, we experienced an internal error, please try again.
The captcha you entered is invalid. Please try again.
Invalid credit card selected. You have been logged out.
Sorry, your team selection was not valid.
Sorry, the payment type chosen is invalid for this event.
Sorry, your billing address was not saved properly, please try again.
Sorry, we experienced an internal error, please try again.
State
Zip Code
Province
Postal Code
County
State/Territory
State/Province
Event Details
Breaking Apps: An Introduction to Web Application Pentesting
This is a 6-hour intensive survey of web security from the vantage point of professional app breakers, delivered over two consecutive Wednesday evenings.
We're offering a brief intro to the principles of application security, followed by hands-on exercises aimed at getting you started actually exploiting application security vulnerabilities. We'll be using Burp Suite, the industry standard tool for web pentesting, and using it to uncover functionality, capture and manipulate HTTP requests, and exploit a wide variety of common and subtle flaws.
Who
Developers who want to know more about the threats their apps face, or want to wipe the smug looks off the face of their next appsec audit team.
QA/QC testers or devops staff who want to integrate more app security testing into their testing, staging, and monitoring plans.
Network security staff who want to move "up the stack" into app testing, and are looking for a strong, assertive push. Particularly testers who have been leaning on automated scanners and would like to lose the crutch.
When
Wednesday, February 22 (Part I: Introduction, Toolchain, Discovery, Manipulation) 6-9pm
Wednesday, February 29 (Part II: Injection) 6-9pm
Where
Morningstar, 22 West Washington Blvd, Chicago, IL
Cost
Free - IF you show up!
There is a $20 registration fee that will be refunded in cash the second you walk in the door on the first day of class.
We tried having events without registration fees, but too many people would sign up and not show up, taking the limited spaces for those who wanted to learn.
All funds left over from Day 1 will be used for food and drinks for the class on Day 2. So, if you sign up and don't go, at least you bought the remaining students some beer and tasty snacks!
Enrollment is limited, so sign up early.
Prerequisites
An interest in breaking web applications. That's mostly it.
No previous experience in web application penetration testing expected or required.
A working knowledge of web development on any stack, from J2EE to Django, would be helpful but is not absolutely required.
You will need to bring a laptop with wireless functionality.
We will send some introductory reading material and toolchain setup instructions to registered students prior to class.
Anti-Prerequisites
If you have experience with testing proxies, finding cross-site scripting, exploiting Clickjacking and blind SQL injection, spidering applications, and all that stuff: this isn't for you. (If you want to help teach, we'd love to talk to you).
High-level outline
- Introduction to Web Application Security Principles
- Building your toolchain
- Discovering content and mapping the attack surface
- Manipulating Requests, including exploiting Insecure Direct Object References
- Injection Attacks, including Cross-Site Scripting and SQL Injection
- Automating Injection Attacks
When & Where
22 W Washington St
Chicago,
IL 60602
Wednesday, February 22, 2012 from 6:00 PM to 9:00 PM (CST)
Add to my calendar
In order to purchase these tickets in installments, you'll need an Eventbrite account. Log in or sign up for a free account to continue.