Search
Skip Navigation Links
Login / Register
Coming Events Coming Events
Tuesday, August 03, 2010
Oxford - Making an Exception
Monday, August 09, 2010
Hereford - Azure Table Service - NoSQL
Monday, August 09, 2010
Coventry - Entity Framework 4
Tuesday, August 17, 2010
Birmingham - I've Got A Little jQuery ...
Wednesday, August 18, 2010
Manchester - An Introduction to F#
Events RSS Feed Event Calendar...
Latest Podcasts Latest Podcasts
Sunday, March 28, 2010
The One with the Great Outdoors
Monday, December 14, 2009
The One With Uncle Jimmy
Monday, December 07, 2009
The One With The 31 Pizzas
Wednesday, September 16, 2009
The One With The Odd Timeline ...
Thursday, July 23, 2009
The One with the stand in
Podcast RSS Podcasts...
Conferences Conferences
Mix10
Mix10
Partner Showcase Partner Showcase
Essential tools for Sql Server and .NET Professionals. Over 95,000 organizations and 200,000 users benefit from our simplicity, ingenuity, and transparent pricing.
Essential tools for Sql Server and .NET Professionals. Over 95,000 organizations and 200,000 users benefit from our simplicity, ingenuity, and transparent pricing.
Powered by ASP.NET 2.0
Course: Advanced Security Training For ASP.NET Developers   
In this 2 day course you will push ASP.NET to the limit and will be shown how ASP.NET applications and environments can be exploited by skilled attackers. Advanced exploitation techniques will be presented together with low-level technical analysis of the .NET Framework. You will also learn advanced defense techniques such including real-time patching of vulnerabilities in the target application, the .Net Framework or the CLR. THIS COURSE IS A MUST FOR ANYBODY WORKING WITH OR INTERESTED IN ASP.NET!
Event Dates
20 Mar 2007
Ashorne Hill
Leamington Spa, Leamington Spa, Warwickshire,
CV33 9QW
Register
Course Details:
Topics

Security Principles, .NET Framework Architecture, Threat Modelling, Discovering Vulnerabilities, Penetration Testing Techniques, Secure Coding Techniques.

Overview

This is an cutting-edge and exciting 2 Day course in which you will push your knowledge of the ASP.NET security framework to the limit. You will be shown how ASP.NET applications and environments can be exploited by skilled attackers. Advanced exploitation techniques will be presented together with low-level technical analysis of the .Net Framework. You will also learn advanced defence techniques such as building an ASP .NET Security Protection Layer how to create Authorization and Data Validation Solutions.

Instructor

Dinis CruzDinis Cruz is a renowned application security expert who is passionate about training developers to move beyond the 'comfort zone' of standard ASP.NET development and into the world of advanced security aware development with the aim of making the Web Applications as secure as possible against malware and malicious hackers. Dinis is also the project leader for the OWASP .Net Project and the and the main developer of several of OWASP .Net tools (SAM'SHE, ANBS, SiteGenerator, PenTest Reporter, ASP.Net Reflector, Online IIS Metabase Explorer). author of many Open Source security tools (see http://www.owasp.org/index.php/.Net).Dinis Cruz

Agenda

The Course is made of 4 modules (2 per day, one in the morning and one in the afternoon)

Module 1: Security Principles and .NET Framework Architecture.
In this module you will lean the principles and architecture of the .NET Framework relating to Security.

Module 2: Threat Modelling and Exploiting ASP.NET Applications.
In this module, you will use quick-and-dirty threat models to discover vulnerabilities in the target application and how to exploit vulnerabilities in ASP.NET Applications, including exploiting Buffer Overflows and Windows vulnerabilities via ASP.NET Applications.

Module 3: Exploiting Full Trust and Partial Trust Asp.Net Environments.
Day 2 will start with a practical demonstration of the power of Full Trust ASP.NET Applications, how attackers could patch the .Net Framework and CLR and launching internal attacks to compromise servers and the data centres. You will also look how to exploiting insecure Partial Trust ASP.NET Environments.

Module 4: Advanced ASP.NET Countermeasures
Now you know what the threats are and what could be done to jeopardise your ASP.NET applications, you will now learn how to defend against these attacks. You will learn how to create secure Data Validation and Authorization architectures, how to create secure ASP.NET hosting environments and how to build an ASP.NET Security Protection.
At the end of this course you will walk away with a much better understanding of some of the weaknesses of .NET applications, particularly the internals of the .NET framework. You will also get the chance to put your skills to the test against a target application over the course of the class.

Equipment Requirements

A laptop with VMWare Player pre-installed. A VMWare image containing all necessary lab tools will be provided.

Knowledge Prerequisites

This is an advanced course targeted at industry professionals who want to understand the weaknesses and the power of the .Net Framework. To get the most of this course the participants should have commercial experience on either application development or security auditing.

Miscellaneous

The course is a 2 day residential course and costs £900 for individuals with discounts available for multiple bookings (this INCLUDES all food for the 2 days and accommodation for one night) . For more details and to register for the course go to http://www.nxtgenug.net/Courses.aspx?courseid=2
Presenters:
Dinis Cruz
Dinis Cruz is a Senior IOActive Security Consultant based in London (UK) and specializes in: ASP.NET Application Security, Active Directory deployments, Application Security audits and .NET Security Curriculum Development. Since the 1.1 release of the .Net Framework, Dinis has been one of the strongest proponents of the need to write .Net applications that can be executed in secure Partially Trusted .Net environments, and has done extensive research on: Rooting the CLR, exposing the dangers of Full Trust Asp.Net Code, Type Confusion vulnerabilities in Full Trust (i.e. non verifiable) code, creating .Net Security Protection Layers and using Reflection to dynamically manipulate .Net Client applications. Dinis is also the current Owasp .Net Project leader and the main developer of several of OWASP .Net tools (SAM'SHE, ANBS, SiteGenerator, PenTest Reporter, Asp.Net Reflector, Online IIS Metabase Explorer).
Copyright © 2006-2009 NxtGenUG - Powered by ASP.NET 3.5