PHP Security Training

The Secure Coding Training for PHP Developers

What do developers learn in a Secure Coding Workshop?

An effective measure for securing your own web application is the training of the development team. The Secure Coding training sharpens the awareness of possible attacks, typical programming errors are recognized, and guidelines are provided for building secure systems. The PHP Security Training specifically addresses the peculiarities of developing secure web applications with PHP.

During the training, basic concepts of web application security and typical attacks on web applications are first addressed. The seminar program is based on the OWASP Top Ten. Subsequently, strategies for avoiding vulnerabilities in the PHP source code and for system hardening are presented. The training is enriched with live hacking demonstrations and framework-specific practical examples (e.g., as Symfony Security Training).

The training can be composed of six training modules and typically lasts at least six hours, depending on the proportion of practice. The training modules are described in more detail on this page below. At the beginning of the training, participants receive the presentation documents. Upon successful participation, each training participant receives a certificate.

  • Risk prevention
  • Illustrative examples
  • Live hacking demonstration
  • Tailor-made seminar
  • PHP security best practices
  • Workshop certificates

Which modules make up the Secure Coding training?

Security Concepts

The principles of secure web development are presented, and a general threat model of a web application is discussed. Similarly, basic security measures and security tests such as penetration tests are discussed to create an understanding of an attacker's view of a web application.

Attacks on Web Applications

The module deals with the dangers of web applications. The most common forms of attack on web applications, the OWASP Top Ten, are discussed: injections, errors in authentication and session management, cross-site scripting (XSS), insecure direct object references, security-relevant misconfiguration, loss of confidentiality of sensitive data, faulty authorization, cross-site request forgery (CSRF), use of components with known vulnerabilities, and unchecked redirects.

Secure Web Development

To mitigate or even ward off the presented attacks, participants are shown possibilities for defense through best practices. Topics such as input validation and output escaping, data storage, authentication management, and session handling are discussed. Programming paradigms and programming itself are also discussed to avoid errors and produce robust code.

Framework-Specific Security

The use of PHP frameworks makes many things easier. Nevertheless, correct implementation is crucial to avoid security vulnerabilities. In this part, framework-specific topics are discussed to implement functionalities securely. Examples include authentication and firewalls, ACLs, as well as error logging and exception handling. We can offer a wide range of PHP frameworks: Symfony (versions 1.x - 3.x), CakePHP, Zend, Drupal, Agavi, Laravel, CodeIgniter, and Yii.

Live Hacking

Through live hacking, it can be impressively shown how attackers bypass mechanisms and compromise systems. This allows developers to develop an awareness of how hackers proceed during attacks, leading to a higher level of security for program code and systems.

Hardening of Web Systems

Secure code is a measure to prevent dangers. However, systems should also be hardened and the attack surface minimized. Approaches are provided to secure systems such as web or database servers and to ensure secure communication. This is done by considering the four levels of information security (protection, deterrence, detection, and response).

Invest in the further education of your employees and in the security of your web applications.

Testimonials for aramido

Dr. Herzig, CEO SearchHaus GmbH

The consultants from aramido convinced me with their extensive expertise and concrete recommendations for measures.

— Dr. Herzig, CEO SearchHaus GmbH