WebApp Sec mailing list archives

Re: looking for advanced web hacking course


From: The Crocodile <tcroc () pasture com>
Date: Wed, 12 Nov 2003 10:13:49 -0500

Tim,

While I agree that it would be difficult to cover EVERY aspect of web
security in a single course, I think it is a bit overkill to state that
"There is no such thing" as a good hands-on advance web hacking course.
Plenty of vendors provide excellent secure programming courses which can
be directly applied to "web hacking" and a vast majority of them are
hands on. They not only show you what to do to exploit the vulnerability
but show you the secure coding practices involved to stop it from
happening.

I also agree that a fundamentally sound programming background helps and
for most good courses it is a class pre-requisite.

Cheers,

--The Crocodile

On Tue, 2003-11-11 at 22:01, Tim Greer wrote:
On Sat, 2003-11-08 at 07:36, Pheebee Buffe wrote:
All,

Anyone know of good, hands-on advanced web hacking course? 

Regards.

There is no such thing.  And if anyone claims otherwise, they are
wanting your money.  This would encompass too much, you are basically
going to need to learn how to program, learn where, how and why exploits
work.


Current thread: