# Security Testing Learning

**URL:** <https://club.ministryoftesting.com/t/security-testing-learning/47954>\
**Category:** Archive\
**Tags:** learning, security\
**Created:** [25 February 2021 11:45 UTC](https://club.ministryoftesting.com/t/security-testing-learning/47954 "2021-02-25T11:45:30Z")\
**Posts on this page:** 14\
**Page:** 1

<div class="post-metadata">

**Author:** ![danielbilling](https://sea2.discourse-cdn.com/flex020/user_avatar/club.ministryoftesting.com/danielbilling/32/8976_2.png) [@danielbilling](https://club.ministryoftesting.com/u/danielbilling)\
**Post date:** [25 February 2021 11:45 UTC](https://club.ministryoftesting.com/t/security-testing-learning/47954/1 "2021-02-25T11:45:30Z")

</div>

I am (finally) working on developing an online security testing course.

This won’t instantly turn everyone into penetration testers, but will, I hope, start to enable, enthuse and develop our exploratory testing skills to include security more and more.

I know what I would want to produce in terms of content, however are there any specific areas of learning or interest that potential learners might want me to cover?

Cheers,  
Dan

---

<div class="post-metadata">

**Author:** ![kristof](https://sea2.discourse-cdn.com/flex020/user_avatar/club.ministryoftesting.com/kristof/32/10839_2.png) [@kristof](https://club.ministryoftesting.com/u/kristof)\
**Post date:** [25 February 2021 15:02 UTC](https://club.ministryoftesting.com/t/security-testing-learning/47954/2 "2021-02-25T15:02:15Z")

</div>

Security testing is pretty broad so if you are asking people like what to cover, could you tell us a bit more about what you had in mind? Are you going to focus on Web Application Security Testing or Network, Phising, Bounty hunting or perhaps risk assessment / ISO’s?

If you are asking for anything I would love to see some War Dialing & Database security scanning 🙂

---

<div class="post-metadata">

**Author:** ![danielbilling](https://sea2.discourse-cdn.com/flex020/user_avatar/club.ministryoftesting.com/danielbilling/32/8976_2.png) [@danielbilling](https://club.ministryoftesting.com/u/danielbilling)\
**Post date:** [25 February 2021 15:21 UTC](https://club.ministryoftesting.com/t/security-testing-learning/47954/3 "2021-02-25T15:21:37Z")

</div>

Ahh…good point…it’ll be web to start with, and then broaden out from there.

---

<div class="post-metadata">

**Author:** ![meowy24](https://sea2.discourse-cdn.com/flex020/user_avatar/club.ministryoftesting.com/meowy24/32/8234_2.png) [@meowy24](https://club.ministryoftesting.com/u/meowy24)\
**Post date:** [25 February 2021 16:04 UTC](https://club.ministryoftesting.com/t/security-testing-learning/47954/4 "2021-02-25T16:04:40Z")

</div>

I just wanted to say ooooooooooooooooooo exciting 😃

---

<div class="post-metadata">

**Author:** ![testthisout](https://avatars.discourse-cdn.com/v4/letter/t/43a26b/32.png) [@testthisout](https://club.ministryoftesting.com/u/testthisout)\
**Post date:** [3 March 2021 09:35 UTC](https://club.ministryoftesting.com/t/security-testing-learning/47954/5 "2021-03-03T09:35:50Z")

</div>

Please please please, can you include suggestions on how to reproduce errors for attracting attention? I mean sometimes I recognize the problem, I test the thing, also fix it but then I do not find an understandable way to say: “look this was dangerous, we are safer now!”.

---

<div class="post-metadata">

**Author:** ![danielbilling](https://sea2.discourse-cdn.com/flex020/user_avatar/club.ministryoftesting.com/danielbilling/32/8976_2.png) [@danielbilling](https://club.ministryoftesting.com/u/danielbilling)\
**Post date:** [3 March 2021 11:10 UTC](https://club.ministryoftesting.com/t/security-testing-learning/47954/6 "2021-03-03T11:10:13Z")

</div>

Can you be a bit more specific on what you mean by ‘attracting attention’? I’m not sure what this means in your context.

---

<div class="post-metadata">

**Author:** ![testthisout](https://avatars.discourse-cdn.com/v4/letter/t/43a26b/32.png) [@testthisout](https://club.ministryoftesting.com/u/testthisout)\
**Post date:** [3 March 2021 11:55 UTC](https://club.ministryoftesting.com/t/security-testing-learning/47954/7 "2021-03-03T11:55:29Z")

</div>

I mean demonstrating the value of your test by demonstrating the risk the business would incur by not solving the issue.  
For example, if your test reproduces the exploit of an IDOR, how should I report it to make clear its priority? Should I state the risks? Should I show a video in which I access a resource I should not be able to access with my permissions? Should I demo it to business and developers?

---

<div class="post-metadata">

**Author:** ![claire.reckless](https://avatars.discourse-cdn.com/v4/letter/c/ba9def/32.png) [@claire.reckless](https://club.ministryoftesting.com/u/claire.reckless)\
**Post date:** [3 March 2021 16:44 UTC](https://club.ministryoftesting.com/t/security-testing-learning/47954/8 "2021-03-03T16:44:13Z")

</div>

Perhaps something around how testers can be involved in , or even set up, threat modelling exercises

---

<div class="post-metadata">

**Author:** ![danielbilling](https://sea2.discourse-cdn.com/flex020/user_avatar/club.ministryoftesting.com/danielbilling/32/8976_2.png) [@danielbilling](https://club.ministryoftesting.com/u/danielbilling)\
**Post date:** [3 March 2021 16:48 UTC](https://club.ministryoftesting.com/t/security-testing-learning/47954/9 "2021-03-03T16:48:55Z")

</div>

This will definitely be part of it

---

<div class="post-metadata">

**Author:** ![fullsnacktester](https://sea2.discourse-cdn.com/flex020/user_avatar/club.ministryoftesting.com/fullsnacktester/32/13479_2.png) [@fullsnacktester](https://club.ministryoftesting.com/u/fullsnacktester)\
**Post date:** [3 March 2021 22:29 UTC](https://club.ministryoftesting.com/t/security-testing-learning/47954/10 "2021-03-03T22:29:28Z")

</div>

> [@claire.reckless](#):
>
> threat modelling

Yes! This would be great, I understand the concept but I’ve never actually taken part!

---

<div class="post-metadata">

**Author:** ![danielbilling](https://sea2.discourse-cdn.com/flex020/user_avatar/club.ministryoftesting.com/danielbilling/32/8976_2.png) [@danielbilling](https://club.ministryoftesting.com/u/danielbilling)\
**Post date:** [4 March 2021 09:56 UTC](https://club.ministryoftesting.com/t/security-testing-learning/47954/11 "2021-03-04T09:56:04Z")

</div>

How about a live threat modelling? @heather_reid is this something we could organise? It’ll be more effective than a course, of which there are many

---

<div class="post-metadata">

**Author:** ![heather\_reid](https://sea2.discourse-cdn.com/flex020/user_avatar/club.ministryoftesting.com/heather_reid/32/29_2.png) [@heather\_reid](https://club.ministryoftesting.com/u/heather_reid)\
**Post date:** [4 March 2021 18:04 UTC](https://club.ministryoftesting.com/t/security-testing-learning/47954/12 "2021-03-04T18:04:32Z")

</div>

Certainly potential 🙂 Pop a proposal through to myself and @mwinteringham and we’ll chat about it.

---

<div class="post-metadata">

**Author:** ![kristof](https://sea2.discourse-cdn.com/flex020/user_avatar/club.ministryoftesting.com/kristof/32/10839_2.png) [@kristof](https://club.ministryoftesting.com/u/kristof)\
**Post date:** [11 June 2021 07:51 UTC](https://club.ministryoftesting.com/t/security-testing-learning/47954/13 "2021-06-11T07:51:46Z")

</div>

@danielbilling how is it going? Is there a table of content available? 😃

++ excited ++

---

<div class="post-metadata">

**Author:** ![danielbilling](https://sea2.discourse-cdn.com/flex020/user_avatar/club.ministryoftesting.com/danielbilling/32/8976_2.png) [@danielbilling](https://club.ministryoftesting.com/u/danielbilling)\
**Post date:** [11 June 2021 08:17 UTC](https://club.ministryoftesting.com/t/security-testing-learning/47954/14 "2021-06-11T08:17:11Z")

</div>

I’ve been working on this as part of the 99 Minute Workshop Instructors course. It seems to be the best way forward.
