Since the SecOps Group came up with a voucher that offered free certification to Certified Appsec Practitioner I will be creating notes here. I will be working on the Certified Appsec Practitioner.
The Course Contents for Certified Appsec Practitioner are as follows:
6. Encoding, Encryption, and Hashing
7. Authentication related Vulnerabilities
8. Understanding of OWASP Top 10 Vulnerabilities
9. Security Best Practices and Hardening Mechanisms.
- Insecure Direct Object Reference (IDOR)
- Privilege Escalation
- Parameter Manipulation attacks
- Securing Cookies.
- Insecure File Uploads
- Code Injection Vulnerabilities
- Business Logic Flaws
- Directory Traversal Vulnerabilities
- Security Misconfigurations.
- Information Disclosure.
- Vulnerable and Outdated Components.
- Common Supply Chain Attacks and Prevention Methods.
We will be following each of the above topics and studying them in detail.