Udemy
    •  
    •  
    •  
    •  
    •  
    •  
    •  
    •  
Turn what you know into an opportunity and reach millions around the world.
Learn More
Your cart is empty.
Keep shopping
Secure Programming of Web Applications - Developers and TPMs
Rating: 4.4 out of 5(5,752 ratings)
10,895 students

Secure Programming of Web Applications - Developers and TPMs

Web Application Security for Software Developers and Technical Project Managers
Created byFrank Hissen
Last updated 6/2026
English

What you'll learn

  • Security of Web Applications
  • Secure Programming Patterns
  • Security Baselines
  • Secure Coding

Course content

5 sections24 lectures1h 49m total length
  • Introduction and Motivation2:32
  • Well-known Vulnerabilities Overview2:28
  • Causes & Background9:22
  • Secure Programming in general3:29

    Apply general secure programming patterns by linking every session and transaction to authenticated users, validating data ranges and content, and preferring whitelisting over blacklisting.

  • BankBoard Intro – A vulnerable Java Web Application3:15

    Intro to BankBoard, a vulnerable Web forum / board without input filtering and other security measures. Purely for demonstrating purposes. If you are only interested in the factual descriptions, you can skip these lectures!

Requirements

  • Web Application Knowledge is a plus
  • Being a Developer

Description

Understand Application Security: Numerous successful attacks on well-known web applications on a weekly basis should be reason enough to study the background of "Web Application Security" of custom-made or self-developed applications.

Computer systems are ubiquitous and part of our working and private everyday life. For companies it is increasingly complex and difficult to keep up their IT security with the current technical progress. Large enterprises establish security processes which are created according to industry standards (e.g., ISO 27001). These processes are very complex and can only be implemented by teams of security experts. Constant quality assurance, maintenance and adaptation also belong to an IT security process.

It does not matter if a company develops products or runs an online shop, IT security is a characteristic feature. Security incidents, which maybe even reach public uncontrolled, do not only damage the business image but may also lead to legal or financial consequences.

  • Intro

  • Typical Vulnerabilities Overview

  • Cause & Background

  • Secure Programming in general

  • Code/Command Injection in general

  • (No)SQL Code Injection

  • Cross-Site Request Forgery (CSRF)

  • Cross-Site Scripting (XSS)

  • Open Redirection

  • File Inclusion / Directory Traversal

  • Clickjacking

  • Session-Hijacking

  • Information Disclosure

  • Attacks on Weaknesses of the Authentication

  • Denial of Service

  • Middleware

  • Third-Party Software

  • Summary and Conclusion

The principles taught in this course are language and platform independent. However, the course will include examples for Java and PHP.

Instructor Frank Hissen, Computer Scientist and Security Expert, teaches IT security for over 20 years and works for companies of all sizes as IT Security Consultant and Software Engineer.


Who this course is for:

  • Software Developer
  • Web Developer