Get in Touch

Course Outline

Introduction to IT Security and Secure Coding

  • Grasping the fundamentals of application security
  • Core principles of secure software development
  • Common security risks in web applications
  • The developer’s role in preventing vulnerabilities

Web Application Security Fundamentals

  • Assessing the web application attack surface
  • Common attack techniques targeting web applications
  • Security principles specific to PHP-based applications
  • Implementing secure development lifecycle practices

Web Application Vulnerabilities

  • An overview of prevalent web vulnerabilities
  • Injection attacks and effective prevention techniques
  • Preventing Cross-Site Scripting (XSS)
  • Mitigating Cross-Site Request Forgery (CSRF)
  • Addressing insecure direct object references and access control issues
  • Implementing secure session management
  • Securing file upload processes

Secure Input Validation and Data Handling

  • The importance of validating and sanitising user input
  • Preventing the processing of malicious data
  • Leveraging PHP validation and filtering features
  • Defending applications against unexpected or malformed input

Client-Side Security

  • Identifying security risks in JavaScript
  • Ensuring secure handling of Ajax requests
  • Addressing HTML5 security considerations
  • Preventing common client-side vulnerabilities
  • Integrating client-side and server-side security practices

Practical Cryptography for PHP Applications

  • Foundational concepts in cryptography
  • Hashing algorithms and password protection
  • Encryption methods and secure data storage
  • Utilising PHP security extensions, including OpenSSL
  • Applying cryptographic best practices

PHP Security Features and Secure Development Techniques

  • PHP security extensions and built-in protections
  • Implementing Ctype, ext/filter, and HTML Purifier
  • Adopting secure coding patterns in PHP
  • Avoiding typical PHP programming errors
  • Securing error and exception handling

PHP Environment Hardening

  • Securing PHP configuration settings
  • Best practices for PHP.ini security
  • Apache and server-level security considerations
  • Managing permissions and application configuration
  • Safeguarding production environments

Advanced PHP Vulnerability Topics

  • Security issues related to time and state
  • Considerations for open_basedir security
  • Scenarios for denial-of-service attacks
  • Hash collision vulnerabilities
  • Current security concerns in the PHP framework

Security Testing and Assessment Techniques

  • An overview of application security testing
  • Utilising security scanners and testing tools
  • Core concepts of penetration testing
  • Using proxy tools, sniffers, and fuzzing techniques
  • Conducting static source code analysis

Practical Secure Coding Workshop

  • Anlysing vulnerable PHP applications
  • Applying practical mitigation techniques
  • Testing and verifying security improvements
  • Reviewing secure coding resources and industry best practices

Requirements

No prior experience required.

 21 Hours

Number of participants


Price per participant

Testimonials (3)

Provisional Upcoming Courses (Require 5+ participants)

Related Categories