Special offers now — see discounted courses.
day
:
hour
:
min
:
sec
See special offers
Writing Secure Code for Android by Infosec

Writing Secure Code for Android by Infosec

25h 29mAdvanced2025-08-04

Authors

Infosec Institute

Infosec Institute

Course details

In this learning path, find out how to incorporate security into Android app development. Learn the pros and cons of Kotlin, the new open-source programming language from JetBrains, which Google adopted for Android. Each course explores a major Android security category and features many examples, so you can observe the impact of missing or poor security in the code. Work with Android Studio and Kotlin online playgrounds to implement security in your code, testing the security mechanism for effectiveness and functionality. Plus, learn where to conduct mobile app and Android-specific vulnerability research online to continue improving your craft.

Learning objectives
Integrate secure coding practices in your Android application development.
Validate input using Kotlin.
Limit the risk of overflows in Android.
Encrypt data in Android.
Protect data at rest, in transit, and in use in Android.
Implement access control in Android apps.
Maintain the integrity of your Android app and device.

Skills covered

Android DevelopmentMobile DevelopmentProgramming LanguagesSoftware DevelopmentOne-Off

Concepts

Introduction to Secure Coding

  • 01 - The need for secure coding
  • 02 - Activity - OWASP Top 10 mobile vulnerabilities, part 1
  • 03 - Activity - OWASP Top 10 mobile vulnerabilities, part 2
  • 04 - Activity - OWASP Top 10 mobile vulnerabilities, part 3
  • 05 - Android security overview
  • 06 - Activity - Researching Android vulnerabilities
  • 07 - Kotlin secure app development overview
  • 08 - Beginner bonus
  • 09 - Activity - Creating a simple app Hello
  • 10 - Activity - Creating a simple app Greeting
  • 11 - Activity - Creating a simple app Sales tax calculator
  • 12 - Activity - Creating a simple app Sales tax calculator, part 2
  • 13 - Activity - Creating a simple app Two activities
  • 14 - Activity - Creating a simple app Two activities, part 2
  • 15 - Activity - Creating a simple app Two activities calculator
  • 16 - Activity - Creating a simple app Two activities calculator, part 2

1. Input Validation

  • 17 - Understanding input risks
  • 18 - Autocompletion, part 1
  • 19 - Autocompletion, part 2
  • 20 - Activity - Securing autocomplete
  • 21 - Special characters, part 1
  • 22 - Special characters, part 2
  • 23 - Activity - Using special characters
  • 24 - Null safety, part 1
  • 25 - Null safety, part 2 - Safe call operator
  • 26 - Null safety, part 3 - Not-null operator
  • 27 - Null safety, part 4 - Elvis operator
  • 28 - Null safety, part 5 - Safe cast and unsafe cast operators
  • 29 - Null safety, part 6 - Smart cast
  • 30 - Activity - Implementing null safety, part 1
  • 31 - Activity - Implementing null safety, part 2
  • 32 - Activity - Implementing null safety, part 3
  • 33 - String interpolation
  • 34 - Activity - Understanding string interpolation
  • 35 - Format string attacks
  • 36 - Regular expressions, part 1
  • 37 - Regular expressions, part 2
  • 38 - Activity - Working with regular expressions in Kotlin, part 1
  • 39 - Activity - Working with regular expressions in Kotlin, part 2
  • 40 - Activity - Validating input with regular expressions in Kotlin, part 3
  • 41 - Input sanitization
  • 42 - Activity - Sanitizing input
  • 43 - Activity - Clamping input to a range
  • 44 - Kotlin filter and trim
  • 45 - Activity - Filtering and trimming
  • 46 - Cross-site attacks
  • 47 - Activity - Exploring cross-site scripting
  • 48 - Cross-app scripting
  • 49 - Activity - Defending against cross-app scripting
  • 50 - Code tampering and injection, part 1
  • 51 - Code tampering and injection, part 2
  • 52 - Code tampering and injection, part 3
  • 53 - Activity - Filtering a malicious QR code, part 1
  • 54 - Activity - Filtering a malicious QR code, part 2
  • 55 - SQL injection
  • 56 - SQL stored procedures
  • 57 - Object deserialization, part 1
  • 58 - Object deserialization, part 2
  • 59 - Activity - Protecting JSON with an API key, part 1
  • 60 - Activity - Protecting JSON with an API key, part 2
  • 61 - Form validation, part 1
  • 62 - Form validation, part 2
  • 63 - Form validation, part 3
  • 64 - Activity - Validating form input, part 1
  • 65 - Activity - Validating form input, part 2
  • 66 - WebView vulnerabilities, part 1
  • 67 - WebView vulnerabilities, part 2
  • 68 - Activity - Securing Android WebView

2. Memory Corruption

  • 69 - Android memory overview
  • 70 - Understanding pointers
  • 71 - Understanding overflows
  • 72 - Activity - Managing overflows

3. Encryption

  • 73 - Android storage overview
  • 74 - Protecting secrets
  • 75 - Activity - Insecurely saving a username and password
  • 76 - Encryption overview
  • 77 - Understanding PKI
  • 78 - Android encryption overview
  • 79 - Activity - Encrypting data, part 1
  • 80 - Activity - Encrypting data, part 2
  • 81 - Activity - Encrypting data, part 3
  • 82 - Hashing
  • 83 - Activity - Hashing a password
  • 84 - Activity - Generating random values
  • 85 - Activity - Salting a hashed password
  • 86 - Android Keystore
  • 87 - Activity - Securely storing secrets in Android Keystore

4. Protecting Data

  • 88 - Common data risks
  • 89 - Android file recovery
  • 90 - Data in transit
  • 91 - Activity - Sniffing clear text transmissions, part 1
  • 92 - Activity - Sniffing clear text transmissions, part 2
  • 93 - Network security
  • 94 - Activity - Configuring network security, part 1
  • 95 - Activity - Configuring network security, part 2
  • 96 - Certificate pinning
  • 97 - Activity - Certificate pinning
  • 98 - Data leakage, part 1
  • 99 - Data leakage, part 2
  • 100 - Activity - Preventing data leakage
  • 101 - Databases
  • 102 - Activity - Working with Room database, part 1
  • 103 - Activity - Working with Room database, part 2
  • 104 - Activity - Securing database data
  • 105 - Android IPC, part 1
  • 106 - Android IPC, part 2 - Activity
  • 107 - Android IPC, part 3 - Service
  • 108 - Android IPC, part 4 - Broadcast receiver
  • 109 - Android IPC, part 4 - Broadcast receiver, continued
  • 110 - Android IPC, part 5 - Content provider
  • 111 - Android IPC, part 5 - Content provider, continued
  • 112 - Android IPC, part 6 - Intent
  • 113 - Android IPC, part 6 - Intent, continued
  • 114 - Android IPC, part 7 - Binder
  • 115 - Android IPC, part 8 - Threads
  • 116 - Android IPC, part 9 - Race condition
  • 117 - Activity - Exploring threads and concurrency

5. Access Control

  • 118 - Authentication, part 1
  • 119 - Authentication, part 2
  • 120 - Activity - Implementing a password checker, part 1
  • 121 - Activity - Implementing a password checker, part 2
  • 122 - Google sign-in
  • 123 - Activity - Signing in with Google and Facebook
  • 124 - Keys, tokens, and secrets
  • 125 - Biometrics
  • 126 - Activity - Implementing biometrics
  • 127 - Two-factor authentication
  • 128 - Authorization, part 1
  • 129 - Authorization, part 2
  • 130 - Authorization, part 3
  • 131 - Activity - Implementing runtime permissions
  • 132 - Activity - Role-based access control
  • 133 - OAuth
  • 134 - Insecure direct object reference
  • 135 - Session management, part 1
  • 136 - Session management, part 2
  • 137 - Activity - Implementing session management

6. Protecting Software and System Integrity

  • 138 - System integrity
  • 139 - Application integrity
  • 140 - Understanding risks of embedding third-party code
  • 141 - Activity - Working with external code
  • 142 - Exception handling, part 1
  • 143 - Exception handling, part 2
  • 144 - Printing and logging, part 1
  • 145 - Printing and logging, part 2
  • 146 - Activity - Handling exceptions, logging and printing, part 1
  • 147 - Activity - Handling exceptions, logging and printing, part 2
  • 148 - Testing types, part 1
  • 149 - Testing types, part 2
  • 150 - Tamper protection
  • 151 - Activity - Reverse engineering an Android app
  • 152 - Root detection
  • 153 - Social engineering
  • 154 - New vulnerability research
  • 155 - Secure Android coding roundup

Conclusion

  • 156 - Final thoughts

About us

LyndaKade is a leading learning platform that helps people learn business, software, technology, and creative skills to achieve personal and professional goals.

Phone numberAparat ChannelTelegram SupportTelegram ChannelInstagram Page

All rights to this site belong to LyndaKade.

Terms of Service|Privacy Policy

نماد الکترونیک enamad در صورت اتصال با آی‌پی داخل کشور، نمایش داده خواهد شد.
logo-samandehi - لوگو ساماندهی
Zarinpal
Zibal