This course equips PHP developers with the essential skills needed to build applications that are resilient against modern internet-based attacks. The curriculum explores web vulnerabilities using practical PHP examples that extend beyond the OWASP Top Ten, addressing a wide range of issues such as various injection attacks, script injections, session handling weaknesses in PHP, insecure direct object references, file upload problems, and more. PHP-specific vulnerabilities are categorized into standard vulnerability types, including missing or inadequate input validation, improper error and exception handling, misuse of security features, and time- and state-related issues. For the latter category, we examine attacks such as open_basedir circumvention, denial-of-service via magic float manipulation, and hash table collision attacks. In every scenario, participants will learn the critical techniques and functions required to mitigate these risks.
A significant emphasis is placed on client-side security, tackling security concerns related to JavaScript, Ajax, and HTML5. The course introduces several PHP security extensions, such as hash, mcrypt, and OpenSSL for cryptographic purposes, as well as Ctype, ext/filter, and HTML Purifier for robust input validation. Best practices for hardening are discussed in the context of PHP configuration (specifically php.ini), Apache, and server-level settings in general. Furthermore, the course provides an overview of various security testing tools and techniques available to developers and testers, including security scanners, penetration testing methods, exploit packs, sniffers, proxy servers, fuzzing tools, and static source code analyzers.
Both the introduction of vulnerability concepts and configuration practices are reinforced through numerous hands-on exercises. These demonstrations illustrate the consequences of successful attacks, show how to apply mitigation strategies, and guide participants in using various extensions and tools effectively.
Participants attending this course will
- Grasp the fundamental concepts of security, IT security, and secure coding
- Understand web vulnerabilities that extend beyond the OWASP Top Ten and learn how to prevent them
- Acquire knowledge of client-side vulnerabilities and secure coding standards
- Develop a practical understanding of cryptography
- Learn to utilize various built-in security features of PHP
- Identify typical coding mistakes and understand how to avoid them
- Stay informed about recent vulnerabilities within the PHP framework
- Gain practical experience in using security testing tools
- Access resources and further readings on secure coding practices
Audience
Developers
Read more...