Web Application Security in Practice – OWASP Top 10 and APIs (HCK4)
Cybersecurity, ICT Security
This course guides you through the most common security mistakes in modern applications based on the current OWASP Top 10, covering not only technical vulnerabilities but also design flaws and process weaknesses that put apps at real-world risk.
The course is highly practical: each topic includes real attack demos, source code analysis and hands-on exercises to solve independently. A dedicated block covers REST and SOAP API security, token management, authorization and practical mitigation techniques.
THIS TRAINING COURSE WILL HELP YOU:
- Understand the OWASP Top 10 and real-world implications
- Identify root causes in code, configuration and design
- Use prevention and detection techniques for real attacks
- Secure REST and SOAP APIs; manage tokens and authorization
- Apply Secure Design principles and perform early threat modeling
WHO SHOULD ATTEND?
- Backend and full-stack developers
- QA and security testers
- DevOps / SRE responsible for deployment and configuration
- Software architects and solution designers
- Security analysts and incident response teams
COURSE LOCATION AND AVAILABLE DATES
Praha + online (optional)
15–16 Feb 2027
596 €
CZECH
Need this course in English?
Public courses are usually delivered in Czech, but this course is also available in English. We can arrange private training for your team online, at your premises or in our classrooms, and tailor the content to your needs.
For groups of around 4 or more participants, private training can already be comparable in price to booking individual places on a public course. Send us your requirements and we’ll recommend the best format and provide an exact quote.
Request training in English
Course content:
Hide details
-
Introduction to application security
-
Attacker mindset and principles of a secure mindset
-
Summary of notable real incidents and their impact
-
Overview of the OWASP project and the Top 10 list
-
Relation to DevSecOps and building security culture
-
A01: Broken Access Control
-
Why access control errors occur
-
Common mistakes: IDOR and missing server-side checks
-
Real incident examples and flawed implementations
-
Prevention and detection of insufficient access control
-
A02: Cryptographic Failures
-
Failures in encrypting data in transit and at rest
-
Misuse of algorithms and incorrect TLS implementations
-
Poor password storage and hashing mistakes
-
Recommendations for storing, transmitting and protecting secrets
-
A03: Injection
-
Types of injection: SQL, OS, LDAP, NoSQL
-
Unvalidated input reaching interpreters
-
Framework influences on inserting values into queries/commands
-
Prevention techniques and safe input handling
-
A04: Insecure Design / SSDLC
-
Difference between design flaws and implementation bugs
-
Principles of secure-by-design systems
-
Threat modeling and risk identification early in development
-
Secure design patterns and practical examples
-
Design review versus late-stage vulnerability fixes
-
A05: Security Misconfiguration
-
Common weaknesses in config files and tools
-
Default accounts, open ports, missing headers, incorrect CORS
-
Importance of secure default settings
-
Automated scanning and configuration checks
-
A06: Vulnerable and Outdated Components
-
Risks of relying on outdated libraries and modules
-
Identifying vulnerabilities via CVEs and SBOMs
-
Update processes and dependency management
-
Importance of testing after updates
-
A07: Identification and Authentication Failures
-
Password breaches, session hijacking, weak authentication
-
Misconfigured cookies and non-rotating tokens
-
Importance of multi-factor authentication (MFA)
-
Differences in authentication between apps and APIs
-
A08: Software and Data Integrity Failures
-
Unverified modules, updates and supply-chain risks
-
Integrity of build processes (CI/CD)
-
Code and update signing practices
-
Trust issues with external repositories and libraries
-
A09: Security Logging and Monitoring Failures
-
What and when to log from a security perspective
-
Relation to forensic analysis and incident detection
-
Common errors: missing logs, unprotected logs
-
Basics of SIEM integration and alerting
-
A10: Server-Side Request Forgery (SSRF)
-
SSRF principles and why it’s increasingly common
-
Examples of handling user URLs or webhooks incorrectly
-
Abuse scenarios in cloud and internal networks
-
Protective measures (allowlists, metadata blocking)
-
REST and SOAP API security
-
Differences between classic apps and REST/SOAP interfaces
-
Inputs, authentication and authorization at the API layer
-
Issues with rate limiting, pagination, IDOR, HPP
-
Token management and tenant data isolation
-
OWASP API Top 10 mapping and design implications
-
Prerequisites:
-
Basic web development or testing knowledge; familiarity with HTTP, web technologies and basic shell use.
-
Schedule:
-
2 days (9:00-17:00)
-
Price per person:
-
596.00 € ( 721.16 € incl. 21% VAT)
Training and learning environment
What does the environment for in-person IT courses look like?We hold training courses in our own classrooms equipped with modern computer equipment for each participant and a large projection screen. Each workstation is fitted with a powerful computer for seamless practical exercises, and the environment supports a calm, friendly atmosphere during training.
Do I need to bring my own laptop to the classroom IT course?Our training rooms are fully equipped, so you do not need to bring your own laptop. A modern computer with all necessary hardware and software is ready for you at your workstation.
Will you receive an official certificate after completing an IT course?Yes, upon successful completion of the training course, you will receive an official ICT Pro certificate confirming your participation and acquired technical skills. You can use it to verify your qualifications or add it to your professional profile.
Where can you find our training center in Brno?The premises of the ICT Pro training center are located on the 1st floor of the COMGUARD building at Sochorova 38 in Brno. Positioned on the border of Žabovřesky and Komín, the location is easily accessible by both car and public transport.
Where can you find our training center in Prague?The premises of the ICT Pro training center are located on the 1st floor of the Opatov Park building at Líbalova 1, Prague 11 – Chodov. The location provides a comfortable environment for your education with convenient access.
What facilities and refreshments are available to you during training breaks?Our training centers feature a fully equipped kitchenette for a comfortable break during your courses. The facilities include a coffee machine, microwave, kettle, and a wide selection of drinks and snacks.
What beverage refreshments are available during your course?A beverage station with a coffee machine, teas, syrups, and water is at your disposal throughout the entire training session. You can enjoy a coffee or another drink of your choice anytime during breaks.
What light refreshments are provided for you during the courses?During course breaks, participants can enjoy light sweet snacks, pastries, and fruit syrups to mix their own drinks. Fresh water dispenser and plates are also available for your convenience.
Should I bring my own snacks to ICT Pro training?There is no need to. A wide selection of savory snacks, sweet biscuits, and snack bars is available for you during breaks. Boost your energy for all-day focus right inside the training center premises.
Can you spend training breaks in the fresh air?Yes, an outdoor terrace is available at our training center. During breaks between learning sessions, you can relax in the fresh air in a pleasant green environment.
Where can you relax during course breaks?Our training center features a spacious outdoor terrace with seating options. During breaks between learning sessions, you can step outside to relax and recharge in the fresh air.