Thank you for sending your enquiry! One of our team members will contact you shortly.
Thank you for sending your booking! One of our team members will contact you shortly.
Course Outline
Introduction to IT Security and Secure Coding
- Foundations of application security
- Core principles of secure software development
- Prevalent security risks in web applications
- The developer's role in vulnerability prevention
Web Application Security Fundamentals
- Analyzing the web application attack surface
- Common methodologies for web application attacks
- Security principles specific to PHP-based applications
- Secure development lifecycle (SDLC) practices
Web Application Vulnerabilities
- Overview of prevalent web vulnerabilities
- Techniques for preventing injection attacks
- Prevention strategies for Cross-Site Scripting (XSS)
- Protection mechanisms for Cross-Site Request Forgery (CSRF)
- Managing insecure direct object references and access control
- Implementing secure session management
- Security considerations for file uploads
Secure Input Validation and Data Handling
- The critical importance of validating and sanitizing user input
- Methods to prevent malicious data processing
- Leveraging PHP's built-in validation and filtering capabilities
- Safeguarding applications against unexpected or malformed input
Client-Side Security
- Identifying security risks associated with JavaScript
- Securing the handling of Ajax requests
- Security considerations for HTML5 implementations
- Strategies for preventing client-side vulnerabilities
- Aligning client-side and server-side security practices
Practical Cryptography for PHP Applications
- Essential concepts in cryptography
- Hashing algorithms and password security
- Encryption methods and secure data storage
- Utilizing PHP security extensions such as OpenSSL
- Implementing cryptographic best practices
PHP Security Features and Secure Development Techniques
- Overview of PHP security extensions and built-in safeguards
- Effective use of Ctype, ext/filter, and HTML Purifier
- Adopting secure coding patterns in PHP
- Avoiding common programming errors that weaken security
- Secure handling of errors and exceptions
PHP Environment Hardening
- Securing critical PHP configuration settings
- Recommended security configurations for php.ini
- Security considerations at the Apache and server level
- Managing file permissions and application settings
- Hardening production environments for optimal security
Advanced PHP Vulnerability Topics
- Security issues related to time and state management
- Security implications of open_basedir restrictions
- Analyzing denial-of-service attack scenarios
- Vulnerabilities arising from hash collisions
- Addressing recent security concerns in the PHP framework
Security Testing and Assessment Techniques
- Introduction to application security testing methodologies
- Employing security scanners and assessment tools
- Core concepts of penetration testing
- Utilizing proxy tools, sniffers, and fuzzing techniques
- Performing static source code analysis
Practical Secure Coding Workshop
- Analyzing vulnerable PHP application code
- Implementing effective mitigation techniques
- Testing and verifying security improvements
- Reviewing authoritative resources and secure coding best practices
Requirements
No prior experience required.
21 Hours
Testimonials (3)
I genuinely enjoyed the real life examples.
Marios Prokopiou
Course - Secure coding in PHP
All topics were well covered and presented with a lot of examples. Ahmed was very efficient and managed to keep us focused and attracted at all times.
Kostas Bastas
Course - Secure coding in PHP
The subject of the course was very interesting and gave us many ideas.