Web Security (module BTI-4203)

Goals of this course

This part of the course aims at providing a good overview of a major software security issues: Web Security.
The students will see the most dangerous web securities issues (for instance XSS, XRSF, SQL injection, ...). They know how such flows can be exploited and know how one can protect a site. They have experienced this attacks on example web sites.

Moodle page

Moodle page for this course

Schedule

The specialisation courses are given on Fridays in Biel (Q415), 8:20 - 11:55.
Course is taught by Kai Brünnler, Emmanuel Benoist. The following schedule represents the courses of the Fall Term 2026-2027.
Day Contents
18.09.2026 K. Bünnler
25.09.2026 K. Bünnler
02.10.2026 K. Bünnler
09.10.2026 K. Bünnler
16.10.2026 K. Bünnler
23.10.2026 K. Bünnler
30.10.2026 Injections
06.11.2026 K. Bünnler
13.11.2026 No course: Bloc week
20.11.2026 Broken Access Control
27.11.2026 Identification or Authentication Failures
04.12.2026 Cryptographic failures
11.12.2026 Cross Site Scripting
18.12.2026 Emmanuel Benoist - Other OWASP Top 10 problems
25.12.2026 No course: Weihnachtsferien / Vacances de Noel
01.01.2027 No course: Weihnachtsferien / Vacances de Noel
08.01.2027 No course: Weihnachtsferien / Vacances de Noel
15.01.2027 Audit-Methodology and Risk Analysis
22.01.2027 No course: Finaltag

Evaluation

This course is part of the module BTI-4203 "Pa" module. Students will pass a written exam (120 minutes for only XML-security and Web-Security (parts taught by E. Benoist and K. Brünler)). This module gives 4 ECTS credits and is part of the Qualification Group C.
This course is also an optional module of the Master of Digital Forensics of the Unil. It counts for 3 ECTS. This module is examinated with an oral exam of 20 minutes.