Veracode Security Labs Champion Level 3 Certificate

The bearer of this certificate earned 300 total points by completing secure coding labs through Veracode Security Labs. Labs are a form of secure code training that involves hands-on-keyboard exercises, where users demonstrate their abilities to exploit and patch code using real applications.
The following labs were completed toward certification:
Lab NameTopic NameLanguagePoints
Own the database [DEPRECATED] OWASP 2017 A1: Injection [DEPRECATED] Python Django10
Down with Uploads [DEPRECATED] OWASP 2017 A7: Cross-Site Scripting (XSS) [DEPRECATED] Python Django20
Parameterize all the things [DEPRECATED] OWASP 2017 A1: Injection [DEPRECATED] Python Django10
Bobby Tables [DEPRECATED] ChallengeOWASP 2017 A1: Injection [DEPRECATED] Python Django10
Really, really bad passwords [DEPRECATED] OWASP 2017 A2: Broken Authentication [DEPRECATED] Python Django10
Hash it, store it, salt - upgrade it [DEPRECATED] OWASP 2017 A2: Broken Authentication [DEPRECATED] Python Django10
Bugs in Debug [DEPRECATED] OWASP 2017 A3: Sensitive Data Exposure [DEPRECATED] Python Django10
eXternal Entity (injection) [DEPRECATED] OWASP 2017 A4: XML External Entities (XXE) [DEPRECATED] Python Django10
XML is always a challenge [DEPRECATED] ChallengeOWASP 2017 A4: XML External Entities (XXE) [DEPRECATED] Python Django10
Suspicious Packages [DEPRECATED] OWASP 2017 A9: Using Components with Known Vulnerabilities [DEPRECATED] Python Django10
In a Pickle [DEPRECATED] OWASP 2017 A8: Insecure Deserialization [DEPRECATED] Python Django10
Helpful Stack Trace [DEPRECATED] ChallengeOWASP 2017 A3: Sensitive Data Exposure [DEPRECATED] Python Django10
Authentication Bypass [DEPRECATED] OWASP 2017 A2: Broken Authentication [DEPRECATED] NodeJS10
Can you see your reflection? [DEPRECATED] OWASP 2017 A7: Cross-Site Scripting (XSS) [DEPRECATED] Python Django10
PII Storage General Application Security: User Data Privacy NodeJS10
Informed Consent General Application Security: User Data Privacy NodeJS10
Access and Erasure General Application Security: User Data Privacy NodeJS20
Rectification General Application Security: User Data Privacy NodeJS10
Data Portability General Application Security: User Data Privacy NodeJS10
Timing is everything [DEPRECATED] ChallengeOWASP 2017 A1: Injection [DEPRECATED] Python Django10
Alert [DEPRECATED] ChallengeOWASP 2017 A7: Cross-Site Scripting (XSS) [DEPRECATED] Python Django10
Persistence [DEPRECATED] ChallengeOWASP 2017 A7: Cross-Site Scripting (XSS) [DEPRECATED] Python Django20
Terrible Password [DEPRECATED] ChallengeOWASP 2017 A2: Broken Authentication [DEPRECATED] Python Flask10
Secret Logging [DEPRECATED] ChallengeOWASP 2017 A3: Sensitive Data Exposure [DEPRECATED] Python Flask10
External Resolution [DEPRECATED] ChallengeOWASP 2017 A4: XML External Entities (XXE) [DEPRECATED] Python Flask10
Deserialization [DEPRECATED] ChallengeOWASP 2017 A8: Insecure Deserialization [DEPRECATED] Python Flask10
Outdated [DEPRECATED] ChallengeOWASP 2017 A9: Using Components with Known Vulnerabilities [DEPRECATED] Python Flask10