This course equips PHP developers with the vital skills needed to build applications that are resilient against modern internet-based threats. It explores web vulnerabilities through practical PHP examples, going beyond the OWASP Top Ten to cover a wide range of injection attacks, script injections, session handling weaknesses, insecure direct object references, file upload flaws, and more. PHP-specific vulnerabilities are categorized into common vulnerability types such as inadequate input validation, improper error and exception handling, misuse of security features, and time- and state-related issues. For the latter, we examine attacks such as open_basedir circumvention, denial-of-service via magic floats, and hash table collision attacks. Throughout, participants will learn the key techniques and functions required to mitigate these risks.
A significant emphasis is placed on client-side security, addressing issues related to JavaScript, Ajax, and HTML5. The course introduces essential PHP security extensions like Hash, Mcrypt, and OpenSSL for cryptography, as well as Ctype, ext/filter, and HTML Purifier for robust input validation. Comprehensive hardening best practices are provided for PHP configuration (including php.ini settings), Apache, and the server environment at large. Additionally, an overview of various security testing tools and methodologies is offered for developers and testers, including security scanners, penetration testing tools, exploit kits, sniffers, proxy servers, fuzzing tools, and static source code analyzers.
Both the theoretical introduction of vulnerabilities and the configuration best practices are reinforced with numerous hands-on exercises. These demonstrate the real-world impact of successful attacks, illustrate how to apply mitigation strategies, and provide practical experience with various extensions and tools.
Participants attending this course will
- Gain a solid understanding of fundamental security concepts, IT security, and secure coding principles
- Learn about web vulnerabilities beyond the OWASP Top Ten and understand how to prevent them
- Explore client-side vulnerabilities and adopt secure coding practices
- Develop a practical understanding of cryptography
- Learn how to leverage various built-in security features of PHP
- Identify common coding mistakes and learn how to avoid them
- Stay informed about the latest vulnerabilities affecting the PHP framework
- Acquire practical skills in using security testing tools
- Receive curated resources and further reading materials on secure coding practices
Audience
Developers
Read more...