01
Secure Software Development
Six sections covering how applications actually get broken into, each ending in a knowledge check.
- Secure design principles — least privilege, defence in depth, fail securely, threat modelling
- Injection attacks — SQL and beyond, and the prevention techniques that hold
- Data attacks and cryptography failures — buffer overflows, race conditions, weak crypto
- Business logic and client-side flaws — XSS, CSRF, API abuse, Content Security Policy
- Access control and authentication — broken access control, IDOR, privilege escalation
- Security testing tools — what each type of testing finds, and how to use them well