SECURING .NET WEB APPLICATIONS (TT8320-N) Training

  • Delivery Method: Online Instructor-Led / Classroom Based / Onsite
  • Participation Model: Public Training / Private / In-House Training
  • Duration: 4 Days
  • Price: From €3,400 +TAX
  • Upcoming Date:
  • UK Based Global Training Provider
Covering OWASP Top Ten, Web Services, Rich Interfaces and more

In this course, you will thoroughly examine best practices for defensively coding .NET web applications, including XML processing and web services. You will repeatedly attack and then defend various assets associated with a fully-functional web application. This hands-on approach drives home the mechanics of how to secure .NET web applications in the most practical of terms. This workshop is a companion course with several developer-oriented courses and seminars. Although this edition of the course is .NET-specific, it may also be presented using JEE or other programming languages.

PCI Compliant Developer Training: Version 3.0 of the Payment Card Information Data Security Standard (PCI-DSS) and the Payment Application Data Security Standard (PA-DSS) have placed an increased emphasis on information security training and awareness. This class can help meet the annual training requirements for your developers and vendors. This secure coding training addresses common coding vulnerabilities in software development processes. This training is used by one of the principle participants in the PCI DSS. Having passed multiple PCI audits, this course has been shown to meet the PCI requirements. The specification of those training requirements are detailed in 6.5.1 through 6.5.10 on pages 55 through 59 of the PCI DSS Requirements 3.0 document dated November 2013.



Who Should Attend?

This intermediate-level .NET programming course is designed for developers who wish to get up and running on developing well-defended software applications.


What You Will Learn

  • Potential sources for untrusted data
  • Consequences for not properly handling untrusted data such as denial of service, cross-site scripting, and injections
  • Test web applications with various attack techniques to determine the existence of and effectiveness of layered defenses
  • Prevent and defend the many potential vulnerabilities associated with untrusted data
  • Vulnerabilities of associated with authentication and authorization
  • Be able to detect, attack, and implement defenses for authentication and authorization functionality and services
  • Dangers and mechanisms behind Cross-Site Scripting (XSS) and Injection attacks
  • Detect, attack, and implement defenses for authentication and authorization functionality and services
  • Concepts and terminology behind defensive, secure, coding
  • Threat Modeling as a tool in identifying software vulnerabilities based on realistic threats against assets
  • Static code reviews and dynamic application testing for uncovering vulnerabilities in web applications
  • Design and develop strong, robust authentication and authorization implementations within the context of .NET
  • Fundamentals of XML Digital Signature and XML Encryption as well as how they are used within the web services arena
  • Detect, attack, and implement defenses for XML-based services and functionality
  • Techniques and measures that can used to harden web and application servers as well as other components in your infrastructure

Training Outline

1. Introduction: Misconceptions

  • Security: The Complete Picture
  • TJX: Anatomy of a Disaster?
  • Causes of Data Breaches
  • Heartland - Slipping Past PCI Compliance
  • Target's Painful Christmas
  • Meaning of Being Compliant
  • Verizon's 2013 Data Breach Report

2. Foundation

  • Security Concepts
    • Motivations: Costs and Standards
    • Open Web Application Security Project
    • Web Application Security Consortium
    • CERT Secure Coding Standards
    • Assets are the Targets
    • Security Activities Cost Resources
    • Threat Modeling
    • System/Trust Boundaries
  • Principles of Information Security
    • Security Is a Lifecycle Issue
    • Minimize Attack Surface Area
    • Layers of Defense: Tenacious D
    • Compartmentalize
    • Consider All Application States
    • Do Not Trust the Untrusted

3. Vulnerabilities

  • Unvalidated Input
    • Buffer Overflows
    • Integer Arithmetic Vulnerabilities
    • Unvalidated Input: From the Web
    • Defending Trust Boundaries
    • Whitelisting vs Blacklisting
  • Overview of Regular Expressions
    • Regular Expressions
    • Working With Regexes in .NET
    • Applying Regular Expressions
  • Broken Access Control
    • Access Control Issues
    • Excessive Privileges
    • Insufficient Flow Control
    • Unprotected URL/Resource Access
    • Examples of Shabby Access Control
    • Session and Session Management
  • Broken Authentication
    • Broken Quality/DoS
    • Authentication Data
    • Username/Password Protection
    • Exploits Magnify Importance
    • Handling Passwords on Server Side
    • Single Sign-on (SSO)
  • Cross Site Scripting (XSS)
    • Persistent XSS
    • Reflective XSS
    • Best Practices for Untrusted Data
  • Injection
    • Injection Flaws
    • SQL Injection Attacks Evolve
    • Drill Down on Stored Procedures
    • Other Forms of Injection
    • Minimizing Injection Flaws
  • Error Handling and Information Leakage
    • Fingerprinting a Web Site
    • Error-Handling Issues
    • Logging In Support of Forensics
    • Solving DLP Challenges
  • Insecure Data Handling
    • Protecting Data Can Mitigate Impact
    • In-Memory Data Handling
    • Secure Pipes
    • Failures in the SSL Framework Are Appearing
  • Insecure Configuration Management
    • System Hardening: IA Mitigation
    • Application Whitelisting
    • Least Privileges
    • Anti-Exploitation
    • Secure Baseline
  • Direct Object Access
    • Dynamic Loading
    • Race Conditions
    • Direct Object References
  • Spoofing, CSRF, and Redirects
    • Name Resolution Vulnerabilities
    • Fake Certs and Mobile Apps
    • Targeted Spoofing Attacks
    • Cross Site Request Forgeries (CSRF)
    • CSRF Defenses are Entirely Server-Side
    • Safe Redirects and Forwards

4. Best Practices

  • .NET Issues and Best Practices
    • Manage Code and Buffer Overflows
    • .NET Permissions
    • ActiveX Controls
    • Proper Exception Handling
  • Understanding What's Important
    • Common Vulnerabilities and Exposures
    • OWASP Top Ten for 2013
    • CWE/SANS Top 25 Most Dangerous SW Errors
    • Monster Mitigations
    • Strength Training: Project Teams/Developers
    • Strength Training: IT Organizations

5. Defending XML, Services, and Rich Interfaces

  • Defending XML
    • XML Signature
    • XML Encryption
    • XML Attacks: Structure
    • XML Attacks: Injection
    • Safe XML Processing
  • Defending Web Services
    • Web Service Security Exposures
    • When Transport-Level Alone is NOT Enough
    • Message-Level Security
    • WS-Security Roadmap
    • Web Service Attacks
    • Web Service Appliance/Gateways
  • Defending Rich Interfaces and REST
    • How Attackers See Rich Interfaces
    • Attack Surface Changes When
    • Moving to Rich Interfaces
    • Bridging and its Potential Problems
    • Three Basic Tenets for Safe Rich Interfaces
    • OWASP REST Security Recommendations

Why Choose Us

Experience SECURING .NET WEB APPLICATIONS (TT8320-N) through Bilginç IT Academy's live and interactive virtual classroom environment. Join a Public course as an individual delegate or arrange a dedicated Private / In-house online training program exclusively for your organization.

  • Delivery Method: Online Instructor-Led
  • Participation Model: Public / Private (In-house)
  • Live and Interactive Training: Connect with your instructor in real time and actively participate through discussions, Q&A sessions, practical exercises, and group activities.
  • Flexible Participation: Join the training from your home, office, or any location with a suitable internet connection.
  • Expert Trainer Network: Learn from experienced trainers with strong industry backgrounds and practical field expertise.
  • Over 30 Years of Training Expertise: Benefit from Bilginç IT Academy's professional training experience since 1995.
  • Worldwide Access: Join our live virtual classrooms from anywhere in the world or arrange a dedicated online training program for your organization.

Experience SECURING .NET WEB APPLICATIONS (TT8320-N) in a professional face-to-face classroom environment. Classroom Based training can be delivered as a Public course open to individual delegates or as a dedicated Private / In-house class exclusively for your organization.

  • Delivery Method: Classroom Based
  • Participation Model: Public / Private (In-house)
  • Face-to-Face Learning: Interact directly with your instructor and fellow delegates in an engaging classroom environment.
  • Experienced Trainers: Learn from specialists with extensive industry experience and practical real-world knowledge.
  • Professional Training Environment: Attend training in comfortable, well-equipped classrooms designed to support effective learning.
  • Practical Learning: Depending on the course, reinforce your knowledge through hands-on exercises, scenarios, case studies, and instructor-led activities.

Arrange SECURING .NET WEB APPLICATIONS (TT8320-N) as a dedicated Onsite training program for your organization. Bilginç IT Academy trainers can deliver the training at your office or another location of your choice, with the program planned around your team's requirements and business objectives.

  • Delivery Method: Onsite
  • Participation Model: Private (In-house)
  • Training at Your Preferred Location: Organize the training at your company's office or another location selected by your organization.
  • Tailored Course Content: Adapt the training program to your projects, team structure, existing skill levels, and specific business requirements.
  • Team-Focused Learning: Develop your team around a shared knowledge base while strengthening internal collaboration and knowledge transfer.
  • Flexible Scheduling: Plan the training dates, location, and program according to your organization's operational requirements.
  • Worldwide Onsite Delivery: Bilginç IT Academy trainers can travel internationally to deliver dedicated training programs at your preferred location.


Contact us for more detail about our trainings and for all other enquiries!

SECURING .NET WEB APPLICATIONS (TT8320-N) Training Course Schedule

Join our public courses in our Istanbul, London and Ankara facilities. Private class trainings will be organized at the location of your preference, according to your schedule.

We can organize this training at your preferred date and location.
05 October 2026 (4 Days)
Istanbul, Ankara, London
€3,400 +TAX
07 October 2026 (4 Days)
Istanbul, Ankara, London
€3,400 +TAX
16 October 2026 (4 Days)
Istanbul, Ankara, London
€3,400 +TAX
18 October 2026 (4 Days)
Istanbul, Ankara, London
€3,400 +TAX
23 October 2026 (4 Days)
Istanbul, Ankara, London
€3,400 +TAX
26 October 2026 (4 Days)
Istanbul, Ankara, London
€3,400 +TAX
17 November 2026 (4 Days)
Istanbul, Ankara, London
€3,400 +TAX
05 January 2027 (4 Days)
Istanbul, Ankara, London
€3,400 +TAX

Our IT training and professional development services reach a global audience, transcending geographical boundaries through advanced digital learning platforms and strategic international hubs. We specialize in delivering world-class curriculum across continents, ensuring that no matter where you are located, you have access to the latest industry certifications and technical expertise. By partnering with global technology leaders and academic institutions, we provide a unified learning experience that meets the demands of a diverse, international workforce. Our commitment to global excellence ensures that professionals in every time zone can master the digital skills required to lead, innovate, and thrive in the ever-evolving global technology landscape.

By using this website you agree to let us use cookies. For further information about our use of cookies, check out our Cookie Policy.