Veracode Security Labs Champion Level 3 Certificate

The bearer of this certificate earned 300 total points by completing secure coding labs through Veracode Security Labs. Labs are a form of secure code training that involves hands-on-keyboard exercises, where users demonstrate their abilities to exploit and patch code using real applications.
The following labs were completed toward certification:
Lab NameTopic NameLanguagePoints
The Art of Redirection General Application Security: CWE-601 Open Redirects NodeJS10
React string sanitization General Application Security: Common React Pitfalls NodeJS10
Sneaky links General Application Security: Common React Pitfalls NodeJS10
Dangerously set HTML links General Application Security: Common React Pitfalls NodeJS10
Sleeping With the Enemy OWASP 8: Software and Data Integrity Failures .NET10
To Protect and To Serve Secure Cookies OWASP 1: Broken Access Control .NET20
Bugs in Debug OWASP 2: Cryptographic Failures NodeJS10
Own the Database OWASP 3: Injection NodeJS10
Parameterize all the things OWASP 3: Injection .NET10
Parameterize all the things OWASP 3: Injection NodeJS10
Can you see your reflection? OWASP 3: Injection NodeJS10
Down with Uploads OWASP 3: Injection NodeJS20
Stored XSS versus CSP OWASP 3: Injection .NET20
Stored XSS versus CSP OWASP 3: Injection NodeJS20
Can you keep a secret? OWASP 5: Security Misconfiguration NodeJS10
eXternal Entity (injection) OWASP 5: Security Misconfiguration .NET10
eXternal Entity (injection) OWASP 5: Security Misconfiguration NodeJS10
Suspicious Packages OWASP 6: Vulnerable and Outdated Components .NET10
Suspicious Packages OWASP 6: Vulnerable and Outdated Components NodeJS10
Tell Mongo "no-go" for untrusted code OWASP 8: Software and Data Integrity Failures NodeJS10
To Protect and To Serve Secure Cookies OWASP 1: Broken Access Control NodeJS10
Get there from here OWASP 10: Server-Side Request Forgery NodeJS10
Valid Deficit OWASP 4: Insecure Design NodeJS10
Loose Lips Sink Servers OWASP 1: Broken Access Control NodeJS10
Valid Deficit OWASP 4: Insecure Design .NET10
Get there from here OWASP 10: Server-Side Request Forgery .NET10