Get in Touch

Course Outline

Introduction to IT Security and Secure Coding

  • Fundamentals of application security.
  • Principles of secure software development.
  • Common security risks in web applications.
  • The developer's role in preventing vulnerabilities.

Web Application Security Fundamentals

  • Understanding the web application attack surface.
  • Common attack techniques against web applications.
  • Security principles for PHP-based applications.
  • Secure development lifecycle practices.

Web Application Vulnerabilities

  • Overview of common web vulnerabilities.
  • Injection attacks and prevention techniques.
  • Cross-Site Scripting (XSS) prevention.
  • Cross-Site Request Forgery (CSRF) protection.
  • Insecure direct object references and access control issues.
  • Secure session management.
  • File upload security considerations.

Secure Input Validation and Data Handling

  • The importance of validating and sanitising user input.
  • Preventing malicious data processing.
  • Utilizing PHP validation and filtering features.
  • Protecting applications from unexpected input.

Client-Side Security

  • Understanding JavaScript security risks.
  • Secure handling of Ajax requests.
  • HTML5 security considerations.
  • Preventing client-side vulnerabilities.
  • Integrating client-side and server-side security practices.

Practical Cryptography for PHP Applications

  • Cryptography fundamentals.
  • Hashing and password protection.
  • Encryption and secure data storage.
  • Using PHP security extensions including OpenSSL.
  • Applying cryptographic best practices.

PHP Security Features and Secure Development Techniques

  • PHP security extensions and built-in protections.
  • Using Ctype, ext/filter, and HTML Purifier.
  • Secure coding patterns in PHP.
  • Avoiding common PHP programming mistakes.
  • Handling errors and exceptions securely.

PHP Environment Hardening

  • Securing PHP configuration settings.
  • Security recommendations for php.ini.
  • Apache and server-level security considerations.
  • Managing permissions and application configuration.
  • Protecting production environments.

Advanced PHP Vulnerability Topics

  • Time and state-related security issues.
  • Open_basedir security considerations.
  • Denial-of-service attack scenarios.
  • Hash collision vulnerabilities.
  • Recent PHP framework security concerns.

Security Testing and Assessment Techniques

  • Overview of application security testing.
  • Using security scanners and testing tools.
  • Penetration testing concepts.
  • Proxy tools, sniffers, and fuzzing techniques.
  • Static source code analysis.

Practical Secure Coding Workshop

  • Analyzing vulnerable PHP applications.
  • Applying mitigation techniques.
  • Testing security improvements.
  • Reviewing secure coding resources and best practices.

Requirements

None.

 21 Hours

Custom Corporate Training

Training solutions designed exclusively for businesses.

  • Customized Content: We adapt the syllabus and practical exercises to the real goals and needs of your project.
  • Flexible Schedule: Dates and times adapted to your team's agenda.
  • Format: Online (live), In-company (at your offices), or Hybrid.
Investment

Price per private group, online live training, starting from 4800 € + VAT*

Contact us for an exact quote and to hear our latest promotions

Testimonials (3)

Provisional Upcoming Courses (Contact Us For More Information)

Related Categories