🚀 Submit a Challenge — SecDim AppSec Village CTF at DEF CON 34 and Win a ROG Xbox Ally

Defensive dApp Workshop

Learn to exploit and defend decentralised applications and smart contracts — hands-on, instructor-led, and modelled on real incidents.

terminal — workshop lab
$ git clone dapp-lab.git$ make exploit✗ Contract drained: reentrancy in withdraw()$ vim contracts/Vault.sol$ make test✓ All security tests passed
Why this workshop

About the Workshop

In this attack and defence workshop, we look at vulnerabilities of decentralised apps and what makes them unique among software vulnerabilities. With beginners in mind, we go under the hood of each vulnerability, understand its internal workings, and find the root cause of the flaw.

What you will learn

We have hand picked security vulnerabilities from both Web2 and Web3 domains. We then attack dApp in a simulated environment and learn how to exploit each vulnerability.

With these insights, we then explore modern defensive design patterns to understand how they protect dApps.

We learn advanced techniques to hunt hard-to-find security bugs and then go one step further to build property-based fuzzers protecting our dApp against possible future security bugs.

At a glance

  • For: Blockchain engineers, Software engineers, Test engineers, DevOps engineers, Tech leads, Code reviewers, and Penetration testers
  • Languages: Solidity, Python, JavaScript, TypeScript (other languages on request)
  • Duration: 4 half-days
  • Delivery: Live online led by Dr. Pedram Hayati
Curriculum

Workshop Modules

A subset of topics is selected based on participants’ skill level and the available class time.

Module 1: Introduction

We have learnt software security the wrong way, let's redefine it.

  • Why we have so many vulnerabilities

  • Web2 vs Web3 vulnerabilities

  • Why post-release patching is dangerous

  • What is Defensive Design and Programming

  • Five phases of identifying and exploiting a vulnerable program

Module 2: Rapid Threat Modelling

Build a rapid, effective and actionable threat model early during development

  • Identify security design issues during stand-ups

  • Trust boundary analysis

  • Five + three threat actors

  • Discover threats

    • Common insecure assumptions in our programs that are exploited

    • Rapid Threat Modelling

    • STRIDE

    • SecDim's Threat Thinking Matrix

  • Build a threat model in an attack and defence game

  • Hack your own app exploitation lab

Module 3: Hunt for security bugs

Hunt for dApp security bugs at run-time using new fuzzing techniques

  • Write security unit tests in brownie

  • Property-based testing using Hypothesis

  • Coverage guided fuzzing

  • Fuzzing vs testing

  • Property-based fuzzing

  • Symbolic execution

  • Swarm fuzzing

  • Stateful fuzzing

Module 4: Follow defensive design patterns

Learn three core defensive design patterns to address the insecure anti-patterns:

  • Transaction order dependency

  • Call before state change

  • Unlimited gas usage

  • Insufficient data validation

  • Lack of data recognition

  • Overlooking an untrusted entry point

  • Security by coding conventions

Module 5: Attack and defend dApps

Learn advanced exploitation techniques to attack dApp security vulnerabilities and then apply defensive design patterns to eliminate the security bugs

  • Reentrancy

  • Denial of Service

  • Block stuffing

  • Front running

  • Numeric overflow

  • Numeric imprecision

  • Visual Spoofing

  • Unicode Vulnerabilities

  • Time Of Check Time Of Use (race condition)

What is included?

  • Step-by-step delivery by a highly qualified instructor
  • Large collection of self-paced git-based labs
  • Access to an exclusive support forum
  • Certificate of completion
  • Full access to workshop content

Limited offer

You will also get:

  • Access to Learn and Play platforms
  • Practice schedule and mentoring
  • Standard pathway program
  • Assessment of your practices
More than a workshop

A Three-Month Pathway, Not a One-Off

We forget almost 60% of newly acquired information within a week. You get a practice schedule and mentorship during a three-month pathway, so secure software engineering becomes your habit.

SecDim standard three-month pathway program
Workshop

Reserve Your Seat Today

Our workshops are offered only a few times a year — don't miss out. Get in touch with our team to reserve your seat and confirm workshop details.