Advanced Dynamic Application Security Testing

I completed TCS iON’s RIO-210 remote internship in Advanced Dynamic Application Security Testing in 2020. It was a 210-hour programme focused on finding and documenting vulnerabilities in web applications.

Category

Cybersecurity

Internship At

Tata Consultancy Services

Start Date

June 18th, 2020

Completion Date

August 11th, 2020

Certification ID

546-7594914-1016

Verification Links

Shaswat advanced dynamic web application testing certificate

About the internship

The programme combined self-study, project work, activity reports and webinars. My project focused on dynamic application security testing (DAST), using tools such as Burp Suite, SQLMap and OWASP ZAP to investigate web application vulnerabilities.

Vulnerabilities I studied

The project covered the OWASP Top 10 categories used at the time, including:

  • Injection and cross-site scripting.
  • Authentication and access control flaws.
  • Sensitive data exposure and XML external entities.
  • Security misconfigurations and insecure deserialisation.
  • Vulnerable components and gaps in logging and monitoring.

OWASP Top 10 vulnerabilities

DAST and SAST

SAST examines source code or binaries without running the application. DAST tests a running application to see how it responds to requests and attack attempts. This internship focused on DAST and also covered how the two approaches differ.

My project work

I used OWASP ZAP and Burp Suite to test running web applications and document findings such as authentication weaknesses and security misconfigurations. The work helped me understand how a vulnerability appears during testing and how to describe it in a report.

Programme information

This page records the internship I completed in 2020. The programme included self-learning modules and an industry project. The provider’s registration information is linked below.

TCS iON Remote Internships portal

How I approached the project

I worked through the vulnerability concepts alongside practical testing. I then brought the findings together in the project report, with an explanation of the issue and the recommended fix.

Project report

The report below contains my internship work. Students can use it as a reference for report structure and documenting their own testing.

This was an early application security project for me. It gave me practice with testing tools and with explaining a technical finding in writing, both of which I continued to use in cybersecurity work.