Exercises
Select ASVS controls; model an endpoint; exploit parser disagreement; repair SQL and command injection; encode multiple output contexts; configure CSP; test CSRF; bypass CORS assumptions; enumerate object authorization; constrain SSRF; race a workflow; redact logs; triage SAST/DAST/SCA; and write disclosure.
Required evidence
Submit authorized reproduction, request and response evidence with secrets removed, code and configuration repair, bypass variants, deterministic regression, ASVS mapping, scope analysis, and residual risk. Raw scanner severity is not accepted without triage.
Oral defense
Demonstrate the violated invariant, explain why the repair generalizes, run a bypass attempt, and identify adjacent routes or versions included in scope.
Source backbone
Use OWASP ASVS, OWASP WSTG, OWASP Cheat Sheets, and NIST SSDF.