Secure Coding
Not a vulnerability taxonomy. The habits that stop you writing the bug in the first place — parameterised queries, contextual encoding, authorization at the boundary, secrets with no fallbacks — each one taught with the check that enforces it and the incident that caused it to be written.
Not yet reviewed
Before you start
- Web Application Securityabout 8h
This course expects those first. Nothing is locked — sign in and it will say where you stand.
The one rule with no exceptions, and why every escaping-by-hand approach has failed.
One-sided — This course teaches writing the version that does not have the bug. The attack each rule prevents is taught in web security, where it is played rather than described; repeating it here would be a worse version of that course.
1 lesson · 3 min
HTML, attribute, JavaScript and URL are four different problems with four different answers.
One-sided — The attack this prevents is cross-site scripting, taught and played in the web security course. This chapter is the writing half.
1 lesson · 3 min
Decided in one place, never in the interface. A hidden button is not an access control.
One-sided — Broken access control is attacked in the web security course. Here it is prevented, which is a different skill and a different chapter.
1 lesson · 3 min
A default secret is the same as no secret, and it is the one that ships.
One-sided — Nothing here is an attack. It is a configuration habit, and the failure it prevents is silent rather than exploited in a lesson.
1 lesson · 3 min
Lockfiles, audits, typosquats, and the transitive dependency nobody read.
One-sided — Supply-chain compromise is an attacker technique and is not taught here as one. This chapter is about the habits that limit what it can reach.
1 lesson · 2 min
Passwords, comparisons, and the difference between an identifier and a secret.
One-sided — The attacks — offline cracking, timing side channels — belong to other courses. Here the subject is choosing the primitive that makes them moot.
1 lesson · 3 min
What the user sees against what the log holds, and why a filename is not a name.
One-sided — Information disclosure and upload handling are prevented here and attacked in the web security course.
1 lesson · 3 min
What to look for, in what order, and why rate limiting is a security control.
One-sided — Review is a reading discipline. There is no attack to pair it with, which is the honest reason rather than an omission.
1 lesson · 3 min
Labs
Hands-on challenges for this course. Each one hides a flag you have to find.
Exam
Timed, and it issues a credential anyone can verify. Practice quizzes are untimed; this one is not.