🔐
Web Security
Defensive security across the stack — XSS, auth, crypto, and application security.
Curriculum · 122 lessons
01Authentication vs Authorizationintro3m02Symmetric versus Asymmetric Encryptionintro4m03The IAM Roles and Policiesintro4m04Cross Site Scripting XSSintro4m05Role Based Access Controlintro4m06The Symmetric Encryption AESintro4m07Cross Site Request Forgery CSRFintro4m08Zero Trust Architectureintro5m09XML External Entity Preventionintro4m10The TLS Handshake in Depthintro5m11The OWASP Top Ten Overviewintro4m12The Asymmetric RSAintro4m13Insecure Direct Object References IDORintro4m14HttpOnly And Secure Cookie Flagsintro4m15Path Traversal Preventionintro4m16The Least Privilege in Cloudintro4m17The AES Block Cipherintro4m18The Hashing SHA Familyintro4m19HTTP Security Headersintro4m20Multi Factor Authenticationintro4m21The Security Headers Checklistintro4m22Certificate Pinningintro4m23The Secrets Manager and KMSintro5m24Clickjacking and Frame Optionscore4m25Secure Cookie Attributes Revisitedcore4m26Security Misconfigurationcore4m27Hashing versus Encryptioncore4m28VPN and Tunnel Securitycore4m29Dependency Vulnerability Scanningcore5m30Rate Limiting as a Defensecore4m31Session Fixation Preventioncore4m32The Principle Of Least Privilegecore4m33Dependency Scanningcore4m34Open Redirect Preventioncore4m35The Man in the Middle Threat Modelcore5m36Secrets Management in Appscore5m37The Salting And Pepperingcore4m38SQL injection & parameterizationcore5m39The Path Traversal Attackcore5m40Defense In Depthcore4m41Security Logging and Monitoringcore5m42Same Site Cookiescore5m43Cipher Modes and the Initialization Vectorcore5m44DNS Security and DNSSECcore5m45The HMAC For Integritycore4m46HMAC Message Authenticationcore4m47Network Segmentationcore4m48JSON Web Tokenscore5m49Server Side Request Forgery SSRFcore5m50Command Injection Preventioncore5m51Salting and Peppering Passwordscore5m52SQL Injection Preventioncore5m53The Block Cipher Modescore5m54The Container Image Scanningcore5m55OAuth Scopes And Consentcore5m56Logging And Audit Trailscore5m57The Random Number Generator and Entropycore5m58The CSRF Token Defensecore5m59Secrets Managementcore5m60Content Security Policy Headerscore5m61API Authorization Checkscore5m62Key Derivation Functionscore5m63Mutual TLS Authenticationcore5m64The Password Hashing Bcrypt Argon2core5m65The Security Groups and NACLscore5m66The Pod Security Standardscore5m67Subresource Integritycore5m68Mass Assignment Protectioncore5m69The Certificate Chain of Trustcore5m70Cross Site Scripting Typescore5m71The Certificate Authoritiescore5m72Password Hashing With bcryptcore5m73Brute Force and Credential Stuffing Defensecore5m74Attribute Based Access Controlcore5m75Server Side Template Injection Defensecore5m76Single Sign On with SAMLcore5m77The Elliptic Curve Cryptocore5m78The VPC Isolation Securitycore5m79Regular Expression Denial Of Service Preventioncore5m80Authenticated Encryption with GCMcore5m81Key Rotationcore5m82OpenID Connectcore5m83The Runtime Container Securitycore5m84Refresh Token Rotationcore5m85Prototype Pollution Defensecore5m86Digital Signaturescore5m87The Kubernetes RBACcore5m88Security Of File Uploadscore6m89Server Side Request Forgerycore5m90The Key Derivation Functionscore5m91The OAuth Authorization Code Flowcore6m92The Network Policies in Kubernetescore5m93The PKCE Extensioncore6m94The Compliance and Benchmarks CIScore5m95Encryption At Rest Vs In Transitadvanced5m96Elliptic Curve Cryptography Basicsadvanced5m97Token Introspection and Revocationadvanced5m98Threat Modeling Basicsadvanced5m99Secure Defaults And Hardeningadvanced5m100Constant Time Comparisonadvanced5m101The Digital Signaturesadvanced5m102Input Validation And Allowlistsadvanced5m103Dependency And Supply Chain Hygieneadvanced6m104The Random Number Generation Cryptoadvanced5m105The Cloud Audit Loggingadvanced6m106TLS Certificates And Chains Of Trustadvanced5m107Insecure Deserializationadvanced5m108WebAuthn And Passkeysadvanced6m109Time Of Check To Time Of Use Racesadvanced6m110Nonce Reuse Dangersadvanced5m111JWT Signature Verification Pitfallsadvanced5m112The Supply Chain Security SBOMadvanced6m113Incident Response Basicsadvanced6m114Secure Session Managementadvanced6m115Supply Chain Attacksadvanced6m116Envelope Encryptionadvanced6m117Business Logic Flaw Reviewadvanced6m118Rate Limiting and Account Lockout Policyadvanced5m119The Threat Modeling Processadvanced6m120The Forward Secrecy In Practiceadvanced5m121The Infrastructure as Code Scanningadvanced6m122The Secure Software Development Lifecycleadvanced6m