Thank you for sending your enquiry! One of our team members will contact you shortly.
Thank you for sending your booking! One of our team members will contact you shortly.
Course Outline
Introduction to IT Security and Secure Coding
- Foundations of application security
- Core principles of secure software development
- Prevalent security risks in web applications
- The developer’s role in vulnerability prevention
Web Application Security Fundamentals
- Mapping the web application attack surface
- Standard attack vectors against web applications
- Security principles specific to PHP-based systems
- Secure development lifecycle methodologies
Web Application Vulnerabilities
- Survey of common web vulnerabilities
- Injection attack vectors and defense mechanisms
- Mitigating Cross-Site Scripting (XSS)
- Safeguarding against Cross-Site Request Forgery (CSRF)
- Managing insecure direct object references and access control
- Implementing secure session management
- Addressing file upload security concerns
Secure Input Validation and Data Handling
- Significance of validating and sanitizing user input
- Blocking malicious data processing
- Leveraging PHP validation and filtering capabilities
- Shielding applications from anomalous input
Client-Side Security
- Assessing JavaScript security threats
- Securing Ajax request handling
- HTML5 security implications
- Preventing client-side exploits
- Aligning client-side and server-side security strategies
Practical Cryptography for PHP Applications
- Core cryptographic concepts
- Hashing algorithms and password security
- Data encryption and secure storage
- Integrating PHP security extensions like OpenSSL
- Applying cryptographic best practices
PHP Security Features and Secure Development Techniques
- PHP security extensions and native protections
- Utilizing Ctype, ext/filter, and HTML Purifier
- Adopting secure coding patterns in PHP
- Eliminating common PHP programming errors
- Secure handling of errors and exceptions
PHP Environment Hardening
- Securing PHP configuration parameters
- php.ini security best practices
- Apache and server-level security measures
- Managing permissions and application settings
- Protecting production environments
Advanced PHP Vulnerability Topics
- Security challenges related to time and state
- Navigating open_basedir security restrictions
- Denial-of-service attack scenarios
- Hash collision vulnerabilities
- Current security concerns in the PHP framework
Security Testing and Assessment Techniques
- Overview of application security testing
- Employing security scanners and testing utilities
- Concepts in penetration testing
- Using proxy tools, sniffers, and fuzzing methods
- Static source code analysis
Practical Secure Coding Workshop
- Analyzing vulnerable PHP applications
- Implementing mitigation strategies
- Validating security enhancements
- Reviewing secure coding resources and industry best practices
Requirements
No prior experience required.
21 Hours
Testimonials (3)
I genuinely enjoyed the real life examples.
Marios Prokopiou
Course - Secure coding in PHP
All topics were well covered and presented with a lot of examples. Ahmed was very efficient and managed to keep us focused and attracted at all times.
Kostas Bastas
Course - Secure coding in PHP
The subject of the course was very interesting and gave us many ideas.