4 / 16 (Wed.) 15:00 - 17:00 4F 4D

Designed for Development Teams: Hands-on Practice Course on Common Web Vulnerabilities

This course is designed for development teams. It eliminates the need to learn complex penetration testing tools (which are not typically used in daily work), install any additional tools (keeping computers clean and uncontaminated), and generate any attack traffic (so companies don't have to worry about accidental misoperations by trainees).


This CyberLab provides a simulate environment with various vulnerabilities from OWASP Top 10 A01-A02. In this course, students will actually use these vulnerabilities to practice attack behaviors, gaining a deeper understanding of how security vulnerabilities are exploited and their effects.

Session Objectives

Through hands-on practice of exploiting these vulnerabilities, students will gain a more intuitive and in-depth understanding of how security vulnerabilities are exploited and their effects, thereby increasing their awareness of potential risks during the development process. This course will enable SAs who are responsible for developing requirements specifications and PGs who write code to consider these attack scenarios before development and avoid dangerous coding practices. It will also enable security officers who need to review security test reports to quickly determine whether these vulnerabilities are "impossible to be exploited by hackers," thereby saving the team's development time.

Session Summary
  • Introduction to Common Vulnerabilities and Hands-on Exercises
  • A01 - Broken Access Control (3 practice questions)
  • Techniques: Passing parameters in URLs, one-click password change, encoding and decoding
  • Vulnerability Exercises: Missing Function Level Access Control, CSRF, Path Traversal
  • A02 - Cryptographic Failures (2 practice questions)
  • Techniques: Browser developer tools
  • Vulnerability Exercises: Plaintext Storage of Passwords, Insecure Randomness
Device Requirement You Should Prepared for

Own laptop (screen no smaller than 14 inches for comfortable operation)

Skills Requirement You Should Have

Basic programming knowledge is required. Web application system development experience is recommended.

Limit on the Number of Attendee
20 people
Sola Chen
SPEAKER
Galaxy Software Services Corporation

TOPIC / TRACK
CyberLAB

LOCATION
Taipei Nangang Exhibition Center, Hall 2
4F 4D

LANGUAGE
Chinese