Get in Touch

Course Outline

Foundations of IT Security and Secure Coding

  • Core principles of application security
  • Principles of secure software development
  • Prevalent security risks in web applications
  • The developer’s role in vulnerability prevention

Basics of Web Application Security

  • Analyzing the attack surface of web applications
  • Common techniques used in web application attacks
  • Security principles for PHP-based systems
  • Integrating security into the development lifecycle

Web Application Vulnerabilities

  • Overview of frequent web vulnerabilities
  • Injection attacks and defensive measures
  • Preventing Cross-Site Scripting (XSS)
  • Mitigating Cross-Site Request Forgery (CSRF)
  • Managing insecure direct object references and access control
  • Implementing secure session management
  • Security best practices for file uploads

Safe Input Validation and Data Processing

  • The criticality of validating and sanitizing user input
  • Preventing the processing of malicious data
  • Leveraging PHP validation and filtering capabilities
  • Safeguarding applications against unexpected inputs

Client-Side Security

  • Identifying security risks in JavaScript
  • Securing Ajax requests
  • Addressing HTML5 security considerations
  • Preventing client-side vulnerabilities
  • Aligning client-side and server-side security strategies

Applied Cryptography in PHP

  • Fundamentals of cryptography
  • Hashing algorithms and password security
  • Encryption and secure data storage
  • Utilizing PHP security extensions such as OpenSSL
  • Implementing cryptographic best practices

PHP Security Features and Secure Development Methods

  • PHP security extensions and native protections
  • Employing Ctype, ext/filter, and HTML Purifier
  • Adopting secure coding patterns in PHP
  • Avoiding typical PHP programming errors
  • Securely managing errors and exceptions

Hardening the PHP Environment

  • Securing PHP configuration parameters
  • Recommendations for PHP.ini security
  • Apache and server-level security measures
  • Managing permissions and application settings
  • Protecting production environments

Advanced PHP Vulnerability Topics

  • Time- and state-related security challenges
  • Security implications of open_basedir
  • Scenarios for denial-of-service attacks
  • Vulnerabilities related to hash collisions
  • Recent security concerns in PHP frameworks

Security Testing and Evaluation Methods

  • Introduction to application security testing
  • Using security scanners and specialized tools
  • Concepts in penetration testing
  • Utilizing proxy tools, sniffers, and fuzzing
  • Static source code analysis

Practical Secure Coding Workshop

  • Analyzing PHP applications with vulnerabilities
  • Implementing mitigation strategies
  • Testing the effectiveness of security enhancements
  • Reviewing secure coding resources and industry best practices

Requirements

No prior experience required.

 21 Hours

Number of participants


Price per participant

Testimonials (3)

Upcoming Courses

Related Categories