PHP is a powerful language for the rapid development of websites, intranet portals or business applications. You will learn to avoid the main vulnerabilities related to web applications, as well as those specific to the PHP platform. This training will also allow you to integrate key best practices into your development cycle to minimize risk and improve the quality of your application. This training covers the essentials of secure development with PHP, from design to deployment.
In particular, the objectives of the training are:
• Bases in development
• Knowledge of the PHP language
• Code : DSWPHP
• Duration : 3 Days
• schedule : 8h30 - 17h30
• place : training center, Center Urbain Nord
• Course materials
• 40% demonstration
• 40% of theory
• 20% practical exercises
• The security context
• Risks incurred and impacts
• History: from the scripting language to today
• The PHP ecosystem
• Cross Site Scripting
• SQL injection
• File inclusion
• Logical vulnerabilities
• Race conditions
• Denial of service
• Remote Code Execution
• Cross Site Request Forgery
• Fixation session
• System
• Web Applications
• Using documentation
• Low typing
• Generating random data
• Time Attacks
• Serialization
• Using compose
• PDO and MNOs
• Frameworks
• Captchas
• Securing flows
• Management of confidential information
• Validation of user input
• Redirection Management
• Management of errors and exceptions
• Unit test
• Continuous integration
• Deployment system
• Static code analysis
Do not hesitate to contact our experts for any additional information, study and free calculation of an audit service.