Thank you for sending your enquiry! One of our team members will contact you shortly.
Thank you for sending your booking! One of our team members will contact you shortly.
Duration 21 hours
Course Outline
Introduction to IT Security and Secure Coding
- Exploring the fundamentals of application security
- Core principles of secure software development
- Identifying common security risks in web applications
- The critical role of developers in vulnerability prevention
Web Application Security Fundamentals
- Analyzing the web application attack surface
- Examining common attack techniques targeting web applications
- Security principles specific to PHP-based applications
- Best practices for the secure development lifecycle
Web Application Vulnerabilities
- Overview of prevalent web vulnerabilities
- Strategies for preventing injection attacks
- Techniques for preventing Cross-Site Scripting (XSS)
- Protecting against Cross-Site Request Forgery (CSRF)
- Addressing insecure direct object references and access control flaws
- Implementing secure session management
- Considerations for securing file uploads
Secure Input Validation and Data Handling
- The importance of validating and sanitizing user input
- Preventing the processing of malicious data
- Leveraging PHP validation and filtering capabilities
- Safeguarding applications against unexpected input
Client-Side Security
- Identifying security risks in JavaScript
- Securing Ajax request handling
- Addressing HTML5 security considerations
- Mitigating client-side vulnerabilities
- Aligning client-side and server-side security practices
Practical Cryptography for PHP Applications
- Foundations of cryptography
- Hashing algorithms and password protection strategies
- Encryption methods and secure data storage
- Utilizing PHP security extensions, including OpenSSL
- Implementing cryptographic best practices
PHP Security Features and Secure Development Techniques
- Exploring PHP security extensions and built-in protections
- Utilizing Ctype, ext/filter, and HTML Purifier
- Adopting secure coding patterns in PHP
- Minimizing common PHP programming errors
- Implementing secure error and exception handling
PHP Environment Hardening
- Securing PHP configuration settings
- Recommended security adjustments for PHP.ini
- Apache and server-level security considerations
- Managing permissions and application configuration
- Protecting production environments
Advanced PHP Vulnerability Topics
- Security issues related to time and state
- Considerations for open_basedir security
- Scenarios for denial-of-service attacks
- Understanding hash collision vulnerabilities
- Addressing recent security concerns in the PHP framework
Security Testing and Assessment Techniques
- Overview of application security testing methodologies
- Using security scanners and specialized testing tools
- Concepts of penetration testing
- Employing proxy tools, sniffers, and fuzzing techniques
- Performing static source code analysis
Practical Secure Coding Workshop
- Analyzing vulnerable PHP applications
- Applying effective mitigation techniques
- Testing security improvements
- Reviewing secure coding resources and industry best practices
Requirements
No prior experience is required.
Testimonials (3)
I genuinely enjoyed the real life examples.
Marios Prokopiou
Course - Secure coding in PHP
All topics were well covered and presented with a lot of examples. Ahmed was very efficient and managed to keep us focused and attracted at all times.
Kostas Bastas
Course - Secure coding in PHP
The subject of the course was very interesting and gave us many ideas.