Veracode Security Labs Champion Level 3 Certificate

The bearer of this certificate earned 300 total points by completing secure coding labs through Veracode Security Labs. Labs are a form of secure code training that involves hands-on-keyboard exercises, where users demonstrate their abilities to exploit and patch code using real applications.
The following labs were completed toward certification:
Lab NameTopic NameLanguagePoints
You've been framed General Application Security: CWE-1021 Improper Restriction of Frames Rails10
Can you keep a secret? [DEPRECATED] OWASP 2017 A6: Security Misconfiguration [DEPRECATED] NodeJS10
No Going Back ChallengeGeneral Application Security: CWE-601 Open Redirects NodeJS10
The Art of Redirection General Application Security: CWE-601 Open Redirects NodeJS10
Forging user requests General Application Security: CWE-352 Cross-Site Request Forgery Python Django10
Check your sources [DEPRECATED] OWASP 2017 A7: Cross-Site Scripting (XSS) [DEPRECATED] Java20
Really, really bad passwords [DEPRECATED] OWASP 2017 A2: Broken Authentication [DEPRECATED] .NET10
In a Pickle [DEPRECATED] OWASP 2017 A8: Insecure Deserialization [DEPRECATED] .NET10
Hash it, store it, salt - upgrade it [DEPRECATED] OWASP 2017 A2: Broken Authentication [DEPRECATED] Java10
Own the database [DEPRECATED] OWASP 2017 A1: Injection [DEPRECATED] .NET10
Parameterize all the things [DEPRECATED] OWASP 2017 A1: Injection [DEPRECATED] .NET10
To Protect and to Serve Secure Cookies [DEPRECATED] OWASP 2017 A5: Broken Access Control [DEPRECATED] .NET20
Jot down this key [DEPRECATED] OWASP 2017 A6: Security Misconfiguration [DEPRECATED] .NET10
Bugs in Debug [DEPRECATED] OWASP 2017 A3: Sensitive Data Exposure [DEPRECATED] .NET10
Down with Uploads [DEPRECATED] OWASP 2017 A7: Cross-Site Scripting (XSS) [DEPRECATED] .NET20
Stored XSS versus CSP [DEPRECATED] OWASP 2017 A7: Cross-Site Scripting (XSS) [DEPRECATED] .NET20
Suspicious Packages [DEPRECATED] OWASP 2017 A9: Using Components with Known Vulnerabilities [DEPRECATED] .NET10
Slow Down [DEPRECATED] OWASP 2017 A10: Insufficient Logging + Monitoring [DEPRECATED] .NET10
Angular HTML and URL sanitization [DEPRECATED] OWASP 2017 A7: Cross-Site Scripting (XSS) [DEPRECATED] Rails10
Can you see your reflection? [DEPRECATED] OWASP 2017 A7: Cross-Site Scripting (XSS) [DEPRECATED] Scala10
Authentication Bypass [DEPRECATED] OWASP 2017 A2: Broken Authentication [DEPRECATED] NodeJS10
Terrible Password [DEPRECATED] ChallengeOWASP 2017 A2: Broken Authentication [DEPRECATED] .NET10
Bulky Updates [DEPRECATED] OWASP 2017 A6: Security Misconfiguration [DEPRECATED] Rails10
Secret Admin [DEPRECATED] ChallengeOWASP 2017 A6: Security Misconfiguration [DEPRECATED] .NET10
Tell Mongo "no-go" for untrusted code [DEPRECATED] OWASP 2017 A8: Insecure Deserialization [DEPRECATED] NodeJS10
eXternal Entity (injection) [DEPRECATED] OWASP 2017 A4: XML External Entities (XXE) [DEPRECATED] .NET10