> ## Content Index
> Fetch the complete content index at: https://coeia.cloud-event.com/llms.txt
> Use this file to discover other available public pages before exploring further.

# Lecture: Web Hacking, Attacks and Defense
- URL: https://coeia.cloud-event.com/en/news/web-hacking-attacks-defense-lecture-en/
- Published: 2017-11-21T09:00:00.000Z
- Updated: 2026-09-26T09:51:24.000Z
- Description: A lecture by Mohd Haji of CoEIA on web application security, covering attacks such as SQLi and XSS and defense-in-depth techniques.
- Author: CoEIA Admin
- Tags: Lectures, #en

**Lecturer:** Mohd Haji

This lecture covers application security topics such as SQL injection (SQLi), cross-site scripting (XSS), command injection, cross-site request forgery (CSRF), local file inclusion (LFI) and OAuth 2.0, focusing on both attacks and defense in depth in web application security. It is aimed at penetration testers who want to learn attack techniques and bypasses for web applications, and at software developers who want to learn defense-in-depth techniques to secure their applications.

Mr. Mohd Haji is a bug hunter and an information security specialist at the Center of Excellence in Information Assurance (CoEIA), King Saud University. He is ranked among the top 100 bug hunters on Bugcrowd globally, was ranked the No. 1 whitehat hacker on Facebook from Hyderabad, India, in 2015, 2016 and 2017, and was twice listed among PayPal's top 10 bug hunters worldwide. He has helped secure more than 100 websites through bug bounty programs, including Google, Microsoft, Facebook and PayPal.

[Watch the lecture recording on YouTube](https://www.youtube.com/watch?v=8wXfUVVxiRY&ref=coeia.cloud-event.com)