Track 09
Security
Learn the security habits needed to protect PHP applications.
Lessons
- Security Model
- User-Submitted Data
- Validation And Normalisation
- Output Escaping
- Cross-Site Scripting (XSS)
- Cross-Site Request Forgery (CSRF)
- SQL Injection
- Authentication And Authorisation Security
- Password Hashing
- Session Security
- Cookie Security
- Upload Security
- Secrets Management
- SSRF, Path Traversal, File Inclusion, And Command Injection
- Mass Assignment And Insecure Direct Object Reference
- JWT And API Token Security
- Rate Limiting And Abuse Prevention
- Cryptographic Randomness
- OpenSSL And Sodium Overview
- Filesystem Security
- Error Display Versus Logging
- Keeping PHP Current
- OWASP Top 10 Orientation For PHP Applications
- Security Review Checklist
- CAPTCHA And Bot Mitigation