Special offers now — see discounted courses.
day
:
hour
:
min
:
sec
See special offers
Programming Foundations: Web Security

Programming Foundations: Web Security

2h 11mBeginner2023-08-02

Authors

Kevin Skoglund

Kevin Skoglund

Founder of NovaFabrica

Course details

Security is a paramount concern when you’re developing websites, but what motivates hackers, what are their most common methods of attack, and most importantly, what can you do to foil their efforts? In this course, instructor Kevin Skoglund details the techniques and mindset that you need to craft solutions for these web security challenges. Learn the eight fundamental principles that underlie all security efforts, the importance of filtering input and controlling output, and how to defend against the most common types of attack. This course can help you, as a developer, to secure your clients’ websites, and offers a great introduction for anyone who wants to learn more about web security.

Skills covered

Software Development SecurityIncident ResponseFoundationsCybersecurity

Concepts

0. Introduction

  • 01 - The importance of security

1. Security Overview

  • 02 - What is security
  • 03 - Why security matters
  • 04 - What is a hacker
  • 05 - Threat models
  • 06 - Total security is unachievable

2. General Security Principles

  • 07 - Least privilege
  • 08 - Simple is more secure
  • 09 - Never trust users
  • 10 - Expect the unexpected
  • 11 - Defense in depth
  • 12 - Resilience
  • 13 - Security through obscurity
  • 14 - Deny-listing and allow-listing
  • 15 - Map exposure points and data passageways

3. Filter Input, Control Output

  • 16 - Regulate requests
  • 17 - Validate input
  • 18 - Sanitize data
  • 19 - Label variables
  • 20 - Keep code private
  • 21 - Keep credentials private
  • 22 - Keep error messages vague
  • 23 - Smart logging

4. The Most Common Attacks

  • 24 - Types of credential attacks
  • 25 - Strong passwords
  • 26 - URL manipulation and Insecure Direct Object Reference (IDOR)
  • 27 - SQL injection
  • 28 - Cross-Site Scripting (XSS)
  • 29 - Cross-Site Request Forgery (CSRF)
  • 30 - Cross-Site Request protections
  • 31 - Cookie visibility and theft
  • 32 - Session hijacking
  • 33 - Session fixation
  • 34 - Remote system execution
  • 35 - File upload abuse
  • 36 - Denial of service

Conclusion

  • 37 - Next steps

About us

LyndaKade is a leading learning platform that helps people learn business, software, technology, and creative skills to achieve personal and professional goals.

Phone numberAparat ChannelTelegram SupportTelegram ChannelInstagram Page

All rights to this site belong to LyndaKade.

Terms of Service|Privacy Policy

نماد الکترونیک enamad در صورت اتصال با آی‌پی داخل کشور، نمایش داده خواهد شد.
logo-samandehi - لوگو ساماندهی
Zarinpal
Zibal