WS2 - From Prompt to PWN: Exploiting LLM Powered Web Applications with OWASP Techniques
Description
Instructed by: Abhinav Verma
Level of Difficulty: Beginner, Intermediate, Advanced
Abstract:
This hands-on workshop explores the offensive security of AI-powered applications where Large Language Models connect to real tools via MCP (Model Context Protocol) servers. Over four hours, participants attack 11 purpose-built AI agents across 9 exercises, exploiting vulnerabilities mapped to the OWASP Top 10 for LLM Applications 2025.
You will perform prompt injection (direct and indirect via RAG poisoning), force AI agents to generate malicious SQL/NoSQL queries through MCP tool interfaces, chain path traversal and SSRF through tool-calling parameters, abuse excessive agency via MCP-exposed CRUD operations, trigger stored XSS through LLM output, and achieve remote code execution via a poisoned supply chain, all through natural language conversation.
This workshop is ideal for red teamers, penetration testers, security engineers, and developers building with LLMs. No prior AI or ML experience is required; every technique is demonstrated before the hands-on lab. Just bring a laptop with a browser.
You walk away with practical experience exploiting 93 attack objectives against live LLM agents, a clear understanding of how traditional web vulnerabilities are amplified through AI tool-calling architectures, and the instincts to spot these risks in your own AI deployments.
Pre-Requisites:
Basic familiarity with web application concepts (HTTP requests, HTML forms, browser developer tools). Understanding of at least one common web vulnerability such as SQL injection, XSS, or SSRF at a conceptual level. No machine learning, AI, Python, or MCP protocol experience required. No prior prompt engineering knowledge needed. Comfort using a web browser and reading JSON responses is sufficient. Students who have used Burp Suite, OWASP ZAP, or browser DevTools will have an advantage, but these tools are not required. All attacks are performed through the platform's chat interfaces.
Tickets for good, not greed Humanitix dedicates 100% of profits from booking fees to charity


