Image
 
linkedin_logo.png rss_logo.jpg
twitter_logo.png youtube_logo.jpg
Latest Additions
 
EH-Net Login
Welcome Guest.






Lost Password?
No account yet? Register
Who's Online
We have 82 guests and 1 member online
EH-Net News Feeds
Latest Additions
 
Advertisement

You are here: Home arrow Forum arrow Ethical Hacking Discussions and Related Certificationsarrow Web Applicationsarrow Prices for Web Application Security courses, your thoughts?
EH-Net
May 26, 2012, 08:54:25 AM *
Welcome, Guest. Please login or register.
Did you miss your activation email?

Login with username, password and session length
News: Advertise on EH-Net!! - Reasonable Rates, Highly Targeted Audience.
 
   Home   Help Calendar Login Register  
Pages: [1]   Go Down
  Print  
Author Topic: Prices for Web Application Security courses, your thoughts?  (Read 1612 times)
0 Members and 2 Guests are viewing this topic.
MaXe
Hero Member
*****
Offline Offline

Posts: 507


I've just upgraded myself to a cyborg muahahaa!!1


View Profile WWW
« on: January 03, 2012, 04:50:35 PM »

Hi EH-netters,


Occasionally I wonder about a variety of things, and some times my questions are best answered by real people.

What I wonder is, what would you think, to be a reasonable price for 1) a beginner course (to web app sec), and 2) a more advanced course?

As I already know the prices for eLearnSecurity and Offensive Security, which I find reasonable even though I don't have enough money to pay for it myself, I wonder what you think  Smiley


Let me hear your thoughts, and also what you expect from 1 and 2, do you expect comprehensive courses, or courses covering the most used attack vectors? Etc.

Off topic comments are more than welcome too.



Best regards,
MaXe
Logged

I'm an InterN0T'er
ajohnson
Recruiters
Hero Member
*
Offline Offline

Posts: 650


aka dynamik


View Profile WWW
« Reply #1 on: January 03, 2012, 05:32:30 PM »

It really depends on what you're offering. If you just make a PowerPoint equivalent to the Web Hackers Handbook, why would it be worth more than the $50 or so dollars for that resource? If you provide audio lectures, instructional videos, challenges/labs, etc., it could be worth significantly more. The others also have the benefit of being relatively established with a potential certification that can be listed as a credential as a resume. The possibility of opening doors provides additional value.

Something that might be interesting would be to take a piece-meal approach to the course and offer various modules (XSS, CSRF, SQLi, Advanced Oracle, Web Shells, Java, Flash, etc.) as $50-100 units. You could possibly offer bundle/subscription pricing (for new modules) as well. This would be useful for some people who may want to brush up on a couple topics, and would be disinclined from purchasing an entire course to do so. At the same time, discounts could be available for someone that wants everything (to briefly answer your original question; I'd say anything from $300-1500 is feasible, depending on what is offered.)

Regarding content, what I really want is to know everything about everything Smiley

Seriously though, you need to balance breadth and depth (that's what she said?). I don't want to be given a high-level overview of a bunch of topics that leaves me with little-to-no practical knowledge, nor do I want to focus on a small number of techniques in excruciating detail that would limit my effectiveness in the real world (i.e. I can only compromise an app in specific scenarios/configurations, even though many other avenues may be available). If you could find content that satisfies the 80/20 Rule/Pareto Principle (80% of the compromises are achieved through 20% of these known vectors/techniques), you'd be off to a good start.

Furthermore, I want to apply what I learn ASAP. You don't need a full-featured application for every point, but something like a collection of PHP scripts would be useful. For example, when discussing XSS, the first script could just take echo the 'q' GET variable back to the user, the second would apply basic filtering and require some encoding, and so on. I really appreciate exercises that reinforce what I'm learning and show me how they can actually be applied/executed.

That was a bit of a ramble, but I HTH.
Logged

WIP: OSCP | www.infosiege.net | @infosiege

The day you stop learning is the day you start becoming obsolete.
MaXe
Hero Member
*****
Offline Offline

Posts: 507


I've just upgraded myself to a cyborg muahahaa!!1


View Profile WWW
« Reply #2 on: January 03, 2012, 06:47:00 PM »

Impressive and very detailed (and nice) reply dynamik, and of course I wasn't talking about a powerpoint presentation of the web hackers handbook, but at least several hours (at least 3-5) of video demonstrations with a PDF file containing some of the background and of course code examples, poc's, etc. Thanks  Smiley
Logged

I'm an InterN0T'er
ajohnson
Recruiters
Hero Member
*
Offline Offline

Posts: 650


aka dynamik


View Profile WWW
« Reply #3 on: January 03, 2012, 09:27:58 PM »

No problem. You've provided quite a few detailed and thorough responses yourself, so I was happy to have an opportunity to reciprocate.

Also, I didn't actually think you would make a PP version of the Web Hackers Handbook Wink I was just using that as a comparison along the lines of, "If that amount of information goes for $50, what are you going to do to justify the extra customer costs that would make your efforts worthwhile."
Logged

WIP: OSCP | www.infosiege.net | @infosiege

The day you stop learning is the day you start becoming obsolete.
Pages: [1]   Go Up
  Print  
 
Jump to:  

Powered by MySQL Powered by PHP Powered by SMF 1.1.16 | SMF © 2011, Simple Machines
Joomla Bridge by JoomlaHacks.com
Valid XHTML 1.0! Valid CSS!
Page created in 0.211 seconds with 19 queries.
 

gk_static-ad_feb2012.jpg
Global Knowledge: Build Security Skills to Protect & Defend

els_130x200fixed2.gif
eLearnSecurity Student Course Now Live!
5% Off with Code
ELS-EH-5

SANS Deals 4 EH-Netters
$150 OFF Any SANS Course in Any Format!
Coupon Code: EHN_Connect Including SANS Security West 2012 & SANSFIRE 2012
Recent Forum Topics

cbtnuggets_logo_125.jpg
Try CBT Nuggets Free!

Vote For EH-Net

Add to Technorati Favorites
technorati fave

 
         
Advertisement

© 2012 The Ethical Hacker Network
Joomla! is Free Software released under the GNU/GPL License.