Track 09

Security

Learn the security habits needed to protect PHP applications.

Lessons

  1. Security Model
  2. User-Submitted Data
  3. Validation And Normalisation
  4. Output Escaping
  5. Cross-Site Scripting (XSS)
  6. Cross-Site Request Forgery (CSRF)
  7. SQL Injection
  8. Authentication And Authorisation Security
  9. Password Hashing
  10. Session Security
  11. Cookie Security
  12. Upload Security
  13. Secrets Management
  14. SSRF, Path Traversal, File Inclusion, And Command Injection
  15. Mass Assignment And Insecure Direct Object Reference
  16. JWT And API Token Security
  17. Rate Limiting And Abuse Prevention
  18. Cryptographic Randomness
  19. OpenSSL And Sodium Overview
  20. Filesystem Security
  21. Error Display Versus Logging
  22. Keeping PHP Current
  23. OWASP Top 10 Orientation For PHP Applications
  24. Security Review Checklist
  25. CAPTCHA And Bot Mitigation