What this course is about
A two-day workshop for development teams, built around your own technology stack. Developers exploit typical vulnerabilities themselves, fix them and learn to spot them in review. Day 1 covers memory safety and embedded C/C++, day 2 covers web, APIs and the review process. The course can be shortened to one day or extended to three, and we can work on anonymised findings from your own code.
Agenda
Day 1: Memory Safety and Embedded Code
Theory
- How attackers think: from bug to exploit
- Buffer overflows, integer errors and format strings
- Undefined behaviour and what compilers do with it
- MISRA C and SEI CERT C: what they cover and what they miss
- Randomness, keys and secrets on embedded devices
Hands-on
- Exploiting a stack overflow in a small firmware parser
- Finding and fixing length and integer bugs in protocol handlers
- Fuzzing a parser and triaging the crashes
- Hardening the build: compiler flags and static analysis
Day 2: Web, APIs and Code Review
Theory
- OWASP Top 10 and OWASP API Security Top 10
- Authentication, sessions and access control (IDOR, BOLA, BFLA)
- Injection and unsafe deserialisation
- Secrets, dependencies and the software supply chain
- Security in the pipeline: SAST, SCA and review gates
Hands-on
- Abusing broken access control in a sample API
- Fixing injection and validation flaws
- Reviewing pull requests with an attacker mindset
- Writing security requirements that can be tested
