Thank you for sending your enquiry! One of our team members will contact you shortly.
Thank you for sending your booking! One of our team members will contact you shortly.
Course Outline
Foundations of IT Security and Secure Coding
- Core principles of application security
- Principles of secure software development
- Prevalent security risks in web applications
- The developer’s role in vulnerability prevention
Basics of Web Application Security
- Analyzing the attack surface of web applications
- Common techniques used in web application attacks
- Security principles for PHP-based systems
- Integrating security into the development lifecycle
Web Application Vulnerabilities
- Overview of frequent web vulnerabilities
- Injection attacks and defensive measures
- Preventing Cross-Site Scripting (XSS)
- Mitigating Cross-Site Request Forgery (CSRF)
- Managing insecure direct object references and access control
- Implementing secure session management
- Security best practices for file uploads
Safe Input Validation and Data Processing
- The criticality of validating and sanitizing user input
- Preventing the processing of malicious data
- Leveraging PHP validation and filtering capabilities
- Safeguarding applications against unexpected inputs
Client-Side Security
- Identifying security risks in JavaScript
- Securing Ajax requests
- Addressing HTML5 security considerations
- Preventing client-side vulnerabilities
- Aligning client-side and server-side security strategies
Applied Cryptography in PHP
- Fundamentals of cryptography
- Hashing algorithms and password security
- Encryption and secure data storage
- Utilizing PHP security extensions such as OpenSSL
- Implementing cryptographic best practices
PHP Security Features and Secure Development Methods
- PHP security extensions and native protections
- Employing Ctype, ext/filter, and HTML Purifier
- Adopting secure coding patterns in PHP
- Avoiding typical PHP programming errors
- Securely managing errors and exceptions
Hardening the PHP Environment
- Securing PHP configuration parameters
- Recommendations for PHP.ini security
- Apache and server-level security measures
- Managing permissions and application settings
- Protecting production environments
Advanced PHP Vulnerability Topics
- Time- and state-related security challenges
- Security implications of open_basedir
- Scenarios for denial-of-service attacks
- Vulnerabilities related to hash collisions
- Recent security concerns in PHP frameworks
Security Testing and Evaluation Methods
- Introduction to application security testing
- Using security scanners and specialized tools
- Concepts in penetration testing
- Utilizing proxy tools, sniffers, and fuzzing
- Static source code analysis
Practical Secure Coding Workshop
- Analyzing PHP applications with vulnerabilities
- Implementing mitigation strategies
- Testing the effectiveness of security enhancements
- Reviewing secure coding resources and industry best practices
Requirements
No prior experience required.
21 Hours
Testimonials (3)
I genuinely enjoyed the real life examples.
Marios Prokopiou
Course - Secure coding in PHP
All topics were well covered and presented with a lot of examples. Ahmed was very efficient and managed to keep us focused and attracted at all times.
Kostas Bastas
Course - Secure coding in PHP
The subject of the course was very interesting and gave us many ideas.