Get in Touch

Course Outline

Foundations of IT Security and Secure Coding

  • Essentials of application security
  • Core principles of secure software development
  • Prevalent security risks in web applications
  • The developer's role in preventing vulnerabilities

Basics of Web Application Security

  • Analyzing the web application attack surface
  • Common attack methodologies targeting web applications
  • Security principles tailored for PHP-based systems
  • Best practices in the secure development lifecycle

Common Web Application Vulnerabilities

  • Survey of frequent web vulnerabilities
  • Techniques for preventing injection attacks
  • Mitigating Cross-Site Scripting (XSS)
  • Protection against Cross-Site Request Forgery (CSRF)
  • Managing insecure direct object references and access control
  • Implementing secure session management
  • Best practices for secure file uploads

Secure Input Validation and Data Management

  • Significance of validating and sanitizing user input
  • Preventing the processing of malicious data
  • Utilizing PHP’s validation and filtering capabilities
  • Safeguarding applications from unexpected or malformed input

Client-Side Security Considerations

  • Identifying security risks in JavaScript
  • Ensuring secure handling of Ajax requests
  • Security implications of HTML5 features
  • Strategies to prevent client-side vulnerabilities
  • Aligning client-side and server-side security measures

Practical Cryptography for PHP

  • Foundations of cryptography
  • Hashing algorithms and password protection
  • Encryption methods and secure data storage
  • Utilizing PHP security extensions like OpenSSL
  • Implementing cryptographic best practices

PHP Security Features and Development Techniques

  • PHP security extensions and built-in safeguards
  • Applying Ctype, ext/filter, and HTML Purifier
  • Secure coding patterns specific to PHP
  • Avoiding frequent PHP programming errors
  • Secure handling of errors and exceptions

Hardening the PHP Environment

  • Securing PHP configuration parameters
  • Recommended settings for php.ini
  • Security considerations for Apache and server-level configurations
  • Managing file permissions and application settings
  • Protecting production environments

Advanced PHP Vulnerability Scenarios

  • Security issues related to time and state management
  • Understanding open_basedir restrictions and bypasses
  • Analyzing denial-of-service attack vectors
  • Exploring hash collision vulnerabilities
  • Recent security concerns in the PHP framework

Security Testing and Assessment Methods

  • Overview of application security testing workflows
  • Using security scanners and assessment tools
  • Concepts of penetration testing
  • Utilizing proxy tools, sniffers, and fuzzing techniques
  • Conducting static source code analysis

Hands-On Secure Coding Workshop

  • Analyzing PHP applications with known vulnerabilities
  • Implementing mitigation strategies
  • Validating security enhancements
  • Reviewing authoritative resources on secure coding

Requirements

No prior experience required.

 21 Hours

Number of participants


Price per participant

Testimonials (3)

Upcoming Courses

Related Categories