Skip to contentExploitQuest
LearnSecure Coding

Secure Coding

Not a vulnerability taxonomy. The habits that stop you writing the bug in the first place — parameterised queries, contextual encoding, authorization at the boundary, secrets with no fallbacks — each one taught with the check that enforces it and the incident that caused it to be written.

Medium

Not yet reviewed

8 chapters8 lessons8 practice quizzes5 hands-on labs1 examabout 6hup to 770 XP

Before you start

This course expects those first. Nothing is locked — sign in and it will say where you stand.

Start the courseParameterise Everything

The one rule with no exceptions, and why every escaping-by-hand approach has failed.

One-sided — This course teaches writing the version that does not have the bug. The attack each rule prevents is taught in web security, where it is played rather than described; repeating it here would be a worse version of that course.

1 lesson · 3 min
  1. Parameterise Everything3 min
  2. Practice quiz5 questions

HTML, attribute, JavaScript and URL are four different problems with four different answers.

One-sided — The attack this prevents is cross-site scripting, taught and played in the web security course. This chapter is the writing half.

1 lesson · 3 min
  1. Four Different Problems3 min
  2. Practice quiz5 questions

Decided in one place, never in the interface. A hidden button is not an access control.

One-sided — Broken access control is attacked in the web security course. Here it is prevented, which is a different skill and a different chapter.

1 lesson · 3 min
  1. One Place To Decide3 min
  2. Practice quiz5 questions

A default secret is the same as no secret, and it is the one that ships.

One-sided — Nothing here is an attack. It is a configuration habit, and the failure it prevents is silent rather than exploited in a lesson.

1 lesson · 3 min
  1. A Default Is No Secret At All3 min
  2. Practice quiz5 questions

Lockfiles, audits, typosquats, and the transitive dependency nobody read.

One-sided — Supply-chain compromise is an attacker technique and is not taught here as one. This chapter is about the habits that limit what it can reach.

1 lesson · 2 min
  1. The Ones You Did Not Choose2 min
  2. Practice quiz5 questions

Passwords, comparisons, and the difference between an identifier and a secret.

One-sided — The attacks — offline cracking, timing side channels — belong to other courses. Here the subject is choosing the primitive that makes them moot.

1 lesson · 3 min
  1. Identifiers Are Not Secrets3 min
  2. Practice quiz5 questions

What the user sees against what the log holds, and why a filename is not a name.

One-sided — Information disclosure and upload handling are prevented here and attacked in the web security course.

1 lesson · 3 min
  1. Errors, and Files You Did Not Name3 min
  2. Practice quiz5 questions

What to look for, in what order, and why rate limiting is a security control.

One-sided — Review is a reading discipline. There is no attack to pair it with, which is the honest reason rather than an omission.

1 lesson · 3 min
  1. What To Look For, In What Order3 min
  2. Practice quiz5 questions

Labs

Hands-on challenges for this course. Each one hides a flag you have to find.

  1. The API Key In The Historydifficulty 2
  2. The Code That Looked Finedifficulty 3
  3. The Package That Wasn'tdifficulty 3
  4. The Profile Picturedifficulty 3
  5. Two At Oncedifficulty 3

Exam

Timed, and it issues a credential anyone can verify. Practice quizzes are untimed; this one is not.

  1. Secure Coding Exam10 questions · pass at 70%