Get in Touch

Course Outline

Foundations of IT Security and Secure Coding

  • Core principles of application security
  • Key tenets of secure software development
  • Common security risks inherent in web applications
  • The developer’s role in preventing vulnerabilities

Web Application Security Essentials

  • Analyzing the web application attack surface
  • Common attack vectors against web applications
  • Security principles specific to PHP-based applications
  • Best practices for the secure development lifecycle

Web Application Vulnerabilities

  • Overview of prevalent web vulnerabilities
  • Injection attacks and effective prevention techniques
  • Strategies for preventing Cross-Site Scripting (XSS)
  • Mechanisms for Cross-Site Request Forgery (CSRF) protection
  • Addressing insecure direct object references and access control flaws
  • Implementing secure session management
  • Security considerations for file uploads

Secure Input Validation and Data Handling

  • The critical importance of validating and sanitizing user input
  • Techniques to prevent the processing of malicious data
  • Leveraging PHP’s native validation and filtering capabilities
  • Safeguarding applications against unexpected or malformed input

Client-Side Security

  • Identifying security risks in JavaScript
  • Securing Ajax request handling
  • HTML5 security implications
  • Preventing common client-side vulnerabilities
  • Integrating client-side and server-side security measures

Practical Cryptography for PHP Applications

  • Foundations of cryptography
  • Hashing algorithms and password protection
  • Encryption methods and secure data storage
  • Utilizing PHP security extensions such as OpenSSL
  • Implementing cryptographic best practices

PHP Security Features and Secure Development Techniques

  • Exploring PHP security extensions and built-in protections
  • Using Ctype, ext/filter, and HTML Purifier
  • Adopting secure coding patterns in PHP
  • Avoiding frequent PHP programming errors
  • Secure handling of errors and exceptions

Hardening the PHP Environment

  • Securing PHP configuration parameters
  • Recommended security settings for PHP.ini
  • Apache and server-level security best practices
  • Managing file permissions and application configurations
  • Protecting production environments

Advanced PHP Vulnerability Topics

  • Security issues related to time and state
  • Open_basedir security implications
  • Scenarios for Denial-of-Service attacks
  • Hash collision vulnerabilities
  • Recent security concerns in the PHP framework

Security Testing and Assessment Methodologies

  • Overview of application security testing
  • Utilizing security scanners and specialized testing tools
  • Concepts in penetration testing
  • Using proxy tools, sniffers, and fuzzing techniques
  • Static source code analysis

Hands-On Secure Coding Workshop

  • Analyzing vulnerable PHP applications
  • Implementing mitigation techniques
  • Testing and verifying security improvements
  • Reviewing secure coding resources and industry best practices

Requirements

No prior experience required.

 21 Hours

Number of participants


Price per participant

Testimonials (3)

Upcoming Courses

Related Categories