Thank you for sending your enquiry! One of our team members will contact you shortly.
Thank you for sending your booking! One of our team members will contact you shortly.
Course Outline
Introduction to IT Security and Secure Coding
- Explaining the fundamentals of application security
- Core principles of secure software development
- Identifying common security risks in web applications
- The developer’s role in preventing vulnerabilities
Web Application Security Fundamentals
- Mapping the web application attack surface
- Reviewing common attack techniques targeting web applications
- Security principles specific to PHP-based applications
- Implementing secure development lifecycle practices
Web Application Vulnerabilities
- Surveying common web vulnerabilities
- Strategies for preventing injection attacks
- Mitigating Cross-Site Scripting (XSS) risks
- Protecting against Cross-Site Request Forgery (CSRF)
- Addressing insecure direct object references and access control flaws
- Implementing secure session management
- Considerations for securing file uploads
Secure Input Validation and Data Handling
- The importance of validating and sanitizing user input
- Preventing the processing of malicious data
- Leveraging PHP’s built-in validation and filtering features
- Safeguarding applications against unexpected inputs
Client-Side Security
- Assessing security risks associated with JavaScript
- Handling Ajax requests securely
- Addressing security considerations in HTML5
- Preventing client-side vulnerabilities
- Aligning client-side and server-side security practices
Practical Cryptography for PHP Applications
- Foundations of cryptography
- Techniques for hashing and password protection
- Encryption methods and secure data storage
- Utilizing PHP security extensions such as OpenSSL
- Applying cryptographic best practices
PHP Security Features and Secure Development Techniques
- Examining PHP security extensions and built-in protections
- Implementing Ctype, ext/filter, and HTML Purifier
- Adopting secure coding patterns in PHP
- Identifying and avoiding common PHP programming errors
- Managing errors and exceptions securely
PHP Environment Hardening
- Securing PHP configuration settings
- Recommended security settings for PHP.ini
- Apache and server-level security measures
- Managing permissions and application configuration
- Protecting production environments
Advanced PHP Vulnerability Topics
- Time- and state-related security challenges
- Security implications of open_basedir
- Scenarios for denial-of-service attacks
- Hash collision vulnerabilities
- Current security concerns in the PHP framework
Security Testing and Assessment Techniques
- An overview of application security testing
- Utilizing security scanners and testing tools
- Concepts in penetration testing
- Employing proxy tools, sniffers, and fuzzing techniques
- Performing static source code analysis
Practical Secure Coding Workshop
- Analyzing vulnerable PHP applications
- Implementing mitigation techniques
- Testing security enhancements
- Reviewing secure coding resources and best practices
Requirements
No prior experience required.
21 Hours
Testimonials (3)
I genuinely enjoyed the real life examples.
Marios Prokopiou
Course - Secure coding in PHP
All topics were well covered and presented with a lot of examples. Ahmed was very efficient and managed to keep us focused and attracted at all times.
Kostas Bastas
Course - Secure coding in PHP
The subject of the course was very interesting and gave us many ideas.