There are too many application security classes that waste time by discussing multiple tools that serve the same purpose, or make application security concepts feel like "magic" by not addressing the practical application of theory. Using the tools I use and the techniques I've learned from years of application security consulting, I provide training that focuses on bringing theory and reality together to provide a true learning experience.
No one wants to hire a consultant without experience, but it's difficult to gain experience unless you already work in the field, or breach ethical boundaries. This is a challenge that many "green" application security professionals face. My training provides real world experience in a classroom environment, allowing for the growth required to enter the work force with confidence and a developed skill set.
Above all, training gives me an opportunity to share my passion for application security with individuals who make a real difference in the state of security for the applications that impact our daily lives. From banks, to social media, to government agencies, the opportunity to support those on the front line of application security is a privilege I don't take for granted.
...but don't take my word for it. Scroll down to see testimonials from previous students.
|April 19-20, 2018||PWAPT||BSides Charleston||Charleston, SC||register|
|June 6-8, 2018||PWAPT||Crowe Horwath LLP||Lexington, KY||register|
|July 16-18, 2018||PWAPT||WIN||Eau Claire, WI||register|
Please contact me for on-site training opportunities.
PWAPT provides comprehensive training on the latest open source tools and manual techniques for performing end-to-end web application penetration testing engagements. After a quick overview of the penetration testing methodology, the instructor will lead students through the process of testing and exploiting a target web application using the techniques and approaches developed from a career of real world application penetration testing experiences. Students will be introduced to the best tools currently available for the specific steps of the methodology, including Burp Suite Pro, and taught how to integrate these tools with manual testing techniques to maximize effectiveness. A major goal of this course is teaching students the glue that brings the tools and techniques together to successfully perform a web application penetration test from beginning to end, an oversight in most web application penetration testing courses. The end result is an individual with the confidence and skill set to conduct consultative web application penetration testing engagements.
The majority of the course will be spent performing an instructor led, hands-on web application penetration test against a target application built specifically for this class using a modern technology stack (Python Flask and React) and including real vulnerabilities as encountered in the wild. No old-school vanilla PHP stuff here folks. Students won't be given overly simplistic steps to execute independently. Rather, at each stage of the test, the instructor will present the goals that each testing task is to accomplish and perform the penetration test in front of the class while students do it on their own machine. Primary emphasis of these instructor led exercises will be placed on how to integrate the tools with manual testing procedures to improve the overall work flow. This experience will help students gain the confidence and knowledge necessary to perform web application penetration tests as an application security professional.
PWAPT is a PortSwigger preferred Burp Suite Training course. PWAPT students will learn basic and advanced usage techniques for Burp Suite Pro, as well as discover obscure functionality hidden within the vast capabilities of the tool. Students will also receive a ~2 week trial license for Burp Suite Pro to use during and after the course.
For additional insight into the origin, mission, and benefits of PWAPT, listen to my interview with Timothy De Block for the Exploring Information Security podcast on the topic of "What is Practical Web Application Penetration Testing?"
Day 4 (optional):
Note: The Conference Edition is an abbreviated version of the course designed to fit into the typical 2-day conference schedule. While not all content can be covered during the Conference Edition courses, all of the content will be provided for self-study.
Students taking this course should have introductory knowledge of the OWASP Top 10. Students do not need to be comfortable with with explaining, finding, or exploiting common web vulnerabilities, but some level of exposure is ideal. This is not an advanced course. However, we will strive to cover advanced topics if the ability level of the student population allows.
This course contains code remediation content that includes discussions on the proper techniques for mitigating vulnerabilities, and exercises where the instructor and students modify the application's source code to implement mitigating controls and test them for effectiveness. While not required, a basic understanding of programming concepts will allow students to better relate to the terminology and techniques demonstrated for properly remediating the discussed vulnerabilities.
Had a great time at @HackWestCon. Especially loved the training by @LaNMaSteR53 for Web App Hacking. Learned a ton of great stuff. Would highly recommend it to anyone looking to learn more about securing websites or finding vulnerabilities in them. #PWAPT— Nathan (@dunetarin) March 27, 2018
And we all loved you for it. Great class, can't say enough good things.— Charles Schultheiss (@testyourbackups) March 24, 2018
Go take this training! I learned a lot from Tim during this class; It changed the way I perform AppSec Testing. https://t.co/u6UKC4WXnV— Keith Hoodlet (@andMYhacks) December 5, 2017
The PWAPT class by @LaNMaSteR53 is nothing short of superb. Very hands on with well built exercises. I highly recommend taking his course.— Ean Meyer (@EanMeyer) October 28, 2017
Tim is the man..... this training is awesome..... tKe a lot of notes even though he walks u through everything... #pro— jeefers (@jeefers) September 25, 2017
@LaNMaSteR53 Great investment of time and money: Tim Tomes' PWAPT class. A must for any web app pen tester. I found it highly beneficial.— Sunny Wear (@SunnyWear) May 29, 2016
Go to this, even if you gotta fly. That's what I did. Totally worth it. https://t.co/C1Gi10XvDb— 7 Minute Security (@7MinSec) February 17, 2016
@LaNMaSteR53 Great class! I loved the hands on nature of it instead of just slides and theory as you get with some other classes.— Kevin Lasher (@KevLasher) January 11, 2016
Had an amazing week in Utah. Went to @LaNMaSteR53's #PWAPT trainingand HackWest. I flew out from California for it on my dime. Worth every penny and then some. Great training, and methodology I could grasp. Thanks Tim!— Aaron Phillips (@EightieOG) March 24, 2018
Finally, thanks to @LaNMaSteR53 for an excellent PWAPT class. Catch you next time my friend!— Jason Wood (@Jason_Wood) March 24, 2018
I can't say enough good things about @LaNMaSteR53 's Practical Web Application Penetration Testing course. Tim delivers information in a very digestible, and immediately useful way. I highly recommend this course to all #AppSec professionals. #PWAPT— Joshua Dow (@0xJDow) February 26, 2018
Our team is learning valuable lessons from @LaNMaSteR53 Practical Web Application Penetration Testing @WWHackinFest - maximize time-boxed results and value-add working through comprehensive methodology and avoiding large deviations— CenterLink Tech (@CenterlinkTech) October 26, 2017
Great job with the class. High energy and good pace. I'm actively suggesting your Boston class to others.— Mike Conley (@yinzsecure) September 22, 2017
@LaNMaSteR53 great PWAPT class. It was awesome getting to learn hands on— Bruce (@brucejadamsjr) September 24, 2016
@LaNMaSteR53 Thanks again for the PWAPT training, you've bridged the gap between what I learned on my own and what I needed to learn next— 67Shepp (@Shepp67) July 27, 2016
If you build software for a living, check out @LaNMaSteR53 and find a way to attend his training.— not a function (@jbaxleyiii) May 18, 2016
I was looking for an affordable, 100% hands-on Webapp pentest course that would teach me a start-to-finish methodology.#PWAPT was all that!— 7 Minute Security (@7MinSec) January 10, 2016
@lanmaster53 It was definitely fun and informative! Thank you for taking the time and effort to put it together and teach it.— Kevin Ahrens (@kahrens) November 7, 2015
@lanmaster53, Thank you again for an awesome class (PWAPT). I paid for it with my own money --ie not my company -- and it was worth it!— Nancy Snoke (@NancySnoke) September 30, 2015
Wooo, epic nose bleed! Thats all the training from @lanmaster53 being stored in my head, forcing the blood out to make room :)— Steve Loughran (@z0rlac) September 25, 2015