Get in Touch
 Duration 21 hours

Course Outline

Introduction to IT Security and Secure Coding

  • Fundamentals of application security
  • Core principles of secure software development
  • Common security risks associated with web applications
  • The developer's role in preventing vulnerabilities

Web Application Security Basics

  • Comprehending the attack surface of web applications
  • Common techniques used to attack web applications
  • Security principles specific to PHP-based applications
  • Practices for a secure development lifecycle

Web Application Vulnerabilities

  • Overview of prevalent web vulnerabilities
  • Injection attacks and strategies for prevention
  • Mitigating Cross-Site Scripting (XSS)
  • Protecting against Cross-Site Request Forgery (CSRF)
  • Addressing insecure direct object references and access control flaws
  • Implementing secure session management
  • Considerations for secure file uploads

Secure Input Validation and Data Handling

  • The importance of validating and sanitising user input
  • Preventing the processing of malicious data
  • Leveraging PHP's validation and filtering features
  • Safeguarding applications against unexpected inputs

Client-Side Security

  • Identifying security risks in JavaScript
  • Handling Ajax requests securely
  • Security considerations for HTML5
  • Preventing client-side vulnerabilities
  • Integrating client-side and server-side security measures

Practical Cryptography for PHP Applications

  • Foundations of cryptography
  • Hashing and password protection mechanisms
  • Encryption and secure data storage
  • Utilising PHP security extensions such as OpenSSL
  • Implementing best practices in cryptography

PHP Security Features and Secure Development Techniques

  • PHP security extensions and built-in protections
  • Using Ctype, ext/filter, and HTML Purifier
  • Secure coding patterns within PHP
  • Avoiding common PHP programming errors
  • Securely handling errors and exceptions

PHP Environment Hardening

  • Securing PHP configuration settings
  • Recommendations for PHP.ini security
  • Apache and server-level security considerations
  • Managing permissions and application configurations
  • Safeguarding production environments

Advanced PHP Vulnerability Topics

  • Security issues related to time and state
  • Considerations regarding open_basedir security
  • Scenarios for denial-of-service attacks
  • Hash collision vulnerabilities
  • Recent security concerns in the PHP framework

Security Testing and Assessment Techniques

  • Overview of application security testing
  • Utilising security scanners and testing tools
  • Concepts in penetration testing
  • Using proxy tools, sniffers, and fuzzing techniques
  • Static source code analysis

Practical Secure Coding Workshop

  • Analyzing vulnerable PHP applications
  • Implementing mitigation techniques
  • Testing security enhancements
  • Reviewing resources and best practices for secure coding

Requirements

None.

Custom Corporate Training

Training solutions designed exclusively for businesses.

  • Customized Content: We adapt the syllabus and practical exercises to the real goals and needs of your project.
  • Flexible Schedule: Dates and times adapted to your team's agenda.
  • Format: Online (live), In-company (at your offices), or Hybrid.
Investment

Price per private group, online live training, starting from 3900 € + VAT*

Contact us for an exact quote and to hear our latest promotions

Testimonials (3)

Provisional Upcoming Courses (Contact Us For More Information)

Related Categories