Thank you for sending your enquiry! One of our team members will contact you shortly.
Thank you for sending your booking! One of our team members will contact you shortly.
Course Outline
Introduction to IT Security and Secure Coding
- Fundamentals of application security
- Principles of secure software development
- Common security risks in web applications
- The developer's role in vulnerability prevention
Web Application Security Fundamentals
- Understanding the web application attack surface
- Common attack techniques targeting web applications
- Security principles for PHP-based applications
- Secure development lifecycle practices
Web Application Vulnerabilities
- Overview of prevalent web vulnerabilities
- Injection attacks and prevention techniques
- Cross-Site Scripting (XSS) mitigation
- Cross-Site Request Forgery (CSRF) protection
- Insecure direct object references and access control flaws
- Secure session management practices
- File upload security considerations
Secure Input Validation and Data Handling
- The importance of validating and sanitising user input
- Preventing the processing of malicious data
- Utilising PHP validation and filtering features
- Protecting applications against unexpected input
Client-Side Security
- Understanding JavaScript security risks
- Secure handling of Ajax requests
- HTML5 security considerations
- Preventing client-side vulnerabilities
- Integrating client-side and server-side security practices
Practical Cryptography for PHP Applications
- Foundations of cryptography
- Hashing mechanisms and password protection
- Encryption and secure data storage
- Using PHP security extensions, including OpenSSL
- Implementing cryptographic best practices
PHP Security Features and Secure Development Techniques
- PHP security extensions and built-in protections
- Utilising Ctype, ext/filter, and HTML Purifier
- Secure coding patterns in PHP
- Avoiding common PHP programming errors
- Secure handling of errors and exceptions
PHP Environment Hardening
- Securing PHP configuration settings
- Security recommendations for php.ini
- Apache and server-level security considerations
- Managing permissions and application configuration
- Safeguarding production environments
Advanced PHP Vulnerability Topics
- Time and state-related security issues
- Security implications of open_basedir
- Denial-of-service attack scenarios
- Hash collision vulnerabilities
- Recent security concerns in the PHP framework
Security Testing and Assessment Techniques
- Overview of application security testing
- Using security scanners and testing tools
- Concepts in penetration testing
- Proxy tools, sniffers, and fuzzing techniques
- Static source code analysis
Practical Secure Coding Workshop
- Analysing vulnerable PHP applications
- Implementing mitigation techniques
- Testing security enhancements
- Reviewing secure coding resources and best practices
Requirements
No prior experience required.
21 Hours
Testimonials (3)
I genuinely enjoyed the real life examples.
Marios Prokopiou
Course - Secure coding in PHP
All topics were well covered and presented with a lot of examples. Ahmed was very efficient and managed to keep us focused and attracted at all times.
Kostas Bastas
Course - Secure coding in PHP
The subject of the course was very interesting and gave us many ideas.