Get in Touch

Course Outline

Introduction to IT Security and Secure Coding

  • Understanding application security fundamentals
  • Principles of secure software development
  • Common security risks in web applications
  • The role of developers in preventing vulnerabilities

Web Application Security Fundamentals

  • Understanding the web application attack surface
  • Common attack techniques against web applications
  • Security principles for PHP-based applications
  • Secure development lifecycle practices

Web Application Vulnerabilities

  • Overview of common web vulnerabilities
  • Injection attacks and prevention techniques
  • Cross-Site Scripting (XSS) prevention
  • Cross-Site Request Forgery (CSRF) protection
  • Insecure direct object references and access control issues
  • Secure session management
  • File upload security considerations

Secure Input Validation and Data Handling

  • Importance of validating and sanitising user input
  • Preventing malicious data processing
  • Using PHP validation and filtering features
  • Protecting applications from unexpected input

Client-Side Security

  • Understanding JavaScript security risks
  • Secure handling of Ajax requests
  • HTML5 security considerations
  • Preventing client-side vulnerabilities
  • Integrating client-side and server-side security practices

Practical Cryptography for PHP Applications

  • Cryptography fundamentals
  • Hashing and password protection
  • Encryption and secure data storage
  • Using PHP security extensions including OpenSSL
  • Applying cryptographic best practices

PHP Security Features and Secure Development Techniques

  • PHP security extensions and built-in protections
  • Using Ctype, ext/filter, and HTML Purifier
  • Secure coding patterns in PHP
  • Avoiding common PHP programming mistakes
  • Handling errors and exceptions securely

PHP Environment Hardening

  • Securing PHP configuration settings
  • PHP.ini security recommendations
  • Apache and server-level security considerations
  • Managing permissions and application configuration
  • Protecting production environments

Advanced PHP Vulnerability Topics

  • Time and state-related security issues
  • Open_basedir security considerations
  • Denial-of-service attack scenarios
  • Hash collision vulnerabilities
  • Recent PHP framework security concerns

Security Testing and Assessment Techniques

  • Overview of application security testing
  • Using security scanners and testing tools
  • Penetration testing concepts
  • Proxy tools, sniffers, and fuzzing techniques
  • Static source code analysis

Practical Secure Coding Workshop

  • Analysing vulnerable PHP applications
  • Applying mitigation techniques
  • Testing security improvements
  • Reviewing secure coding resources and best practices

Requirements

None.

 21 Hours

Number of participants


Price per participant

Testimonials (3)

Upcoming Courses

Related Categories