Masterclass

Injection Inspection: Defending Against Data Manipulation Attacks

read description ↓

A full-day hands-on workshop where developers identify, exploit, and fix common injection vulnerabilities in web apps. Examples provided in Python, JavaScript, and .NET so participants can work in their preferred language.

Workshop Structure

Hour 1: SQL Injection (~50 min)

Intro, vulnerable app demo, exploitation lab, remediation implementation, Q&A.

Hour 2: Command Injection (~50 min)

Intro, vulnerable app demo, exploitation lab, remediation implementation, Q&A.

Hour 3: Command Injection & Cross-Site Scripting (XSS) (~55 min)

Intro, vulnerable app demo, "Eval is Evil" segment, exploitation lab, remediation implementation, Q&A.

Hour 4: Deserialization Vulnerabilities (~50 min)

Intro, vulnerable app demo, exploitation lab, remediation implementation, Q&A.

Hours 5–6: JWT Token Manipulation (~110 min)

Build it: JWT overview, common use cases, integrate a JWT in a web app. Break it: Exploit flaws like decode vs. verify, bad signing, token expiration, denial of service, wrong storage, leaking secrets. Fix it: Step-by-step remediation of exploited flaws.

Hour 7 (Bonus, time permitting)

Other injection techniques, including AI tooling injection.

Exercise Format:

Each section includes pre-configured app code in multiple languages, step-by-step exploitation instructions, example attack payloads, secure code templates, and verification methods.

Requirements

Laptop required. All exercises run locally. Participants should complete pre-distributed setup instructions beforehand; at minimum, Docker and git must be installed and functioning and one language interpreter should be installed and functioning (ideally Python or JavaScript).

For web developers, security engineers, and technical leads

8 July 2026, Berlin

Full-day masterclass. Only 30 spots.

Speaker

Wekoslav Stefanovski

Head of Development at Sourcico

Learn MORE ↓

Wekoslav Stefanovski has about two decade of professional developer experience using a variety of development technologies. Has been using C# since the first public beta, and has a long and fruitful love relationship with it. Has been using JavaScript since the previous millennium and has a long and fruitful love/hate relationship with it. Currently, works at Sourcico as Head of development. He is passionate about functional programming, static code analysis, compiler design and code quality metrics.

Bozidar Spirovski

Chief Information Security Officer @ Blue dot and @ Sourcico. Founder @ BeyondMachines

Learn MORE ↓

Spirovski Bozidar has over 20 years of experience in cybersecurity. He believes that cybersecurity is not just about technology but is integral to every aspect of an organization. By working closely with teams, Bozidar aims to integrate cybersecurity features as a standard practice in product development. He also stresses the importance of leadership in fostering individual growth and providing consistent support. Bozidar has held significant roles in various companies. He is the Chief Information Security Officer at Blue dot and Sourcico, with previous tenure in SaaS startups as well as large enterprises in the banking, telco and energy sectors. At EVN, H4 and Blue dot he played a pivotal role in setting up the InfoSec organizations and achieving approval by security teams of the largest companies in the world as customers. He also founded BeyondMachines, creating a cybersecurity threat awareness platform and mentoring engineering students.

Access to Masterclass
Full-Day Masterclass Pass • 8 July 2026
Tech Expo - Full Access
40k sqm Full Experience • 9-10 July 2026
Workshops
Pre-registration required • 8 July 2026
Official Congress Party
Official Congress App
Certificate of Participation
Recordings
Fast Lane
Plus Lounge
Exclusive area for networking, lunch, snacks and refreshments
Speakers Lounge
VIP Lounge
Networking for executives & decision-makers
Tech Leaders Night • 8 July 2026
Evening event for executives & special guests
VIP Badge

Masterclass Pass

Now only
€ 379
Single Ticket
Regular price: € 699
Whats included?

Congress Pass & Masterclass Pass

Now only
€ 699
Single Ticket
Regular price: € 1,199
Whats included?

Check out other masterclasses

Advanced AI Systems with MCP, Memory & Human-in-the-Loop

Hosted by:

Sebastian Gingter

Christian Weyer

Learn More

The Software Engineer 2030: From Coder to AI Orchestrator?

Hosted by:

Patrick Schnell

Learn More

Mastering Software Architecture

Hosted by:

David Tielke

Learn More

Big Data and AI Architecture: Apache Iceberg, Spark and LLMs

Hosted by:

Pratik Patel

Learn More

Cross-Framework Frontend Performance Bootcamp

Hosted by:

Peter Kröner

Learn More

Spec First Development: Building and Modernizing Apps with Agentic AI

Hosted by:

Julia Kordick

Learn More

Mastering Modern Architecture: Building Flexible, Distributed Systems with Hands-On Code

Hosted by:

Oliver Sturm

Learn More

Deep Dive Workshop: AI for Enterprise Developers

Hosted by:

Dr. Damir Dobric

Learn More

Let the spec speak: Building intelligent tests with Gherkin and Playwright

Hosted by:

Elio Struyf

Luise Freese

Learn More

Building Infrastructure Tools with Kubernetes Operators and Go

Hosted by:

Rabieh Fashwall

Learn More

Observability Masterclass with OpenTelemetry: Designing, Implementing & Debugging Production Systems

Hosted by:

Shramish Kafle

Learn More

Cloud-Native Testing: A Hands-On Masterclass for Modern Infrastructure

Hosted by:

Moataz Nabil

Learn More

Event-Driven Microservices: Patterns and Practices for Production-Ready Systems

Hosted by:

Lutz Huehnken

Learn More

From Chaos to Blueprint: Rapid Architecture for Greenfield & Legacy Systems

Hosted by:

Hendrik Lösch

Learn More

Designing architecture and code that’s easy to change and test

Hosted by:

Dennis Doomen

Learn More

Modern Angular Architectures: SignalStore, Signal Forms, and Agentic UI

Hosted by:

Manfred Steyer

Learn More

The Cake Is a Lie: Fixing (Login) Accessibility

Hosted by:

Ramona Schwering

Learn More

Injection Inspection: Defending Against Data Manipulation Attacks

Hosted by:

Wekoslav Stefanovski

Bozidar Spirovski

Learn More

Taming Hallucinations in Production: Hands-On Masterclass on Agents and RAG Systems

Hosted by:

Miriam Kümmel

Learn More

GitHub Copilot Masterclass: From Autocomplete to Virtual Agents

Hosted by:

Marc Müller

Neno Loje

Learn More

Can’t find a specific topic you would love to see as a Masterclass? Reach out to us at tickets@wearedevelopers.com