BSides Munich 2024

How to Hack your Web Application
2024-11-09 , Hochschule München - R1.008

You always wanted to know how web applications are getting hacked? This is your chance. Learn how attackers will get into your web application and how you can defend.


This is a beginners' workshop on web application security. No prerequisites in web application security are required. A certain (web application) development background is beneficial.

  • First, we will be playing a virtual escaple the room game with challenges on a web application to get into an attacker's mindset.
  • Then follows a quick introduction to the OWASP Top 10 vulnerabilities.
  • Finally use the gathered knowledge so far to attack a vulnerable web application (https://github.com/Phylu/vulnerable-click-game) and see how these attacks can easily be prevented.

Please bring your (fully charged) laptop to be able to participate.


Which keywords describe your submission?:

web application, appsec, sqlinjection, xss, rce

Janosch Braukmann, ne Maier is a passionated entrepreneur, DevOps engineer and speaker. After his studies in Informatics and Educational Science he founded the start-up Crashtest Security. Janosch published his research on the border between computer science and psychology. He has been educating others on DevSecOps as a speaker on IT security and related topices for the last several years. Currently, Janosch is working as Team Lead System Engineering & Information Security Officer at ottonova.