• Home
  • Learn
  • Feed
  • Ladder
  • Saved
← Paths
🔐

Web Security

Defensive security across the stack — XSS, auth, crypto, and application security.

Curriculum · 146 lessons

01Authentication vs Authorizationintro3m02Symmetric versus Asymmetric Encryptionintro4m03The IAM Roles and Policiesintro4m04Cross Site Scripting XSSintro4m05Role Based Access Controlintro4m06The Symmetric Encryption AESintro4m07Cross Site Request Forgery CSRFintro4m08Zero Trust Architectureintro5m09XML External Entity Preventionintro4m10The TLS Handshake in Depthintro5m11The OWASP Top Ten Overviewintro4m12The Asymmetric RSAintro4m13Insecure Direct Object References IDORintro4m14HttpOnly And Secure Cookie Flagsintro4m15Path Traversal Preventionintro4m16The Least Privilege in Cloudintro4m17The AES Block Cipherintro4m18The Hashing SHA Familyintro4m19HTTP Security Headersintro4m20Multi Factor Authenticationintro4m21The Security Headers Checklistintro4m22Password Spraying Attacksintro3m23Certificate Pinningintro4m24The Secrets Manager and KMSintro5m25Typosquatting In Package Registriesintro3m26Public Object Storage Exposureintro3m27Coordinated Vulnerability Disclosureintro4m28HTTP Parameter Pollutioncore4m29Step Up Authenticationcore4m30Clickjacking and Frame Optionscore4m31Secure Cookie Attributes Revisitedcore4m32Security Misconfigurationcore4m33Hashing versus Encryptioncore4m34VPN and Tunnel Securitycore4m35Dependency Vulnerability Scanningcore5m36Host Header Injectioncore4m37Rate Limiting as a Defensecore4m38Session Fixation Preventioncore4m39The Principle Of Least Privilegecore4m40Dependency Scanningcore4m41Open Redirect Preventioncore4m42The Man in the Middle Threat Modelcore5m43Secrets Management in Appscore5m44The Salting And Pepperingcore4m45Machine To Machine Auth With Client Credentialscore4m46SQL injection & parameterizationcore5m47The Path Traversal Attackcore5m48Defense In Depthcore4m49Security Logging and Monitoringcore5m50Same Site Cookiescore5m51Cipher Modes and the Initialization Vectorcore5m52DNS Security and DNSSECcore5m53The HMAC For Integritycore4m54LDAP Injectioncore4m55HMAC Message Authenticationcore4m56Network Segmentationcore4m57JSON Web Tokenscore5m58Server Side Request Forgery SSRFcore5m59Command Injection Preventioncore5m60Salting and Peppering Passwordscore5m61SQL Injection Preventioncore5m62The Block Cipher Modescore5m63The Container Image Scanningcore5m64NoSQL Injectioncore4m65OAuth Scopes And Consentcore5m66Logging And Audit Trailscore5m67The Random Number Generator and Entropycore5m68The CSRF Token Defensecore5m69Secrets Managementcore5m70Content Security Policy Headerscore5m71API Authorization Checkscore5m72Key Derivation Functionscore5m73Mutual TLS Authenticationcore5m74The Password Hashing Bcrypt Argon2core5m75The Security Groups and NACLscore5m76The Pod Security Standardscore5m77Code Signing And Signature Verificationcore4m78Subresource Integritycore5m79Mass Assignment Protectioncore5m80The Certificate Chain of Trustcore5m81Cross Site Scripting Typescore5m82The Certificate Authoritiescore5m83Password Hashing With bcryptcore5m84Brute Force and Credential Stuffing Defensecore5m85Attribute Based Access Controlcore5m86Server Side Template Injection Defensecore5m87Single Sign On with SAMLcore5m88The Elliptic Curve Cryptocore5m89The VPC Isolation Securitycore5m90The OAuth Device Authorization Flowcore5m91Regular Expression Denial Of Service Preventioncore5m92Authenticated Encryption with GCMcore5m93Key Rotationcore5m94OpenID Connectcore5m95The Runtime Container Securitycore5m96Protocol Downgrade Attackscore4m97Refresh Token Rotationcore5m98Prototype Pollution Defensecore5m99Digital Signaturescore5m100The Kubernetes RBACcore5m101Security Of File Uploadscore6m102Server Side Request Forgerycore5m103The Key Derivation Functionscore5m104Dependency Confusion Attackscore4m105The OAuth Authorization Code Flowcore6m106The Network Policies in Kubernetescore5m107The PKCE Extensioncore6m108The Compliance and Benchmarks CIScore5m109Hardware Security Modulescore4m110Protecting The Cloud Metadata Servicecore4m111Rotating Signing Keys With JWKSadvanced5m112Restricting Syscalls With Seccompadvanced5m113DNS Rebindingadvanced5m114Log4Shell And JNDI Injectionadvanced5m115Timing Side Channel Attacksadvanced5m116Encryption At Rest Vs In Transitadvanced5m117Elliptic Curve Cryptography Basicsadvanced5m118Web Cache Poisoningadvanced5m119Token Introspection and Revocationadvanced5m120Threat Modeling Basicsadvanced5m121Secure Defaults And Hardeningadvanced5m122Constant Time Comparisonadvanced5m123The Digital Signaturesadvanced5m124Input Validation And Allowlistsadvanced5m125Dependency And Supply Chain Hygieneadvanced6m126The Random Number Generation Cryptoadvanced5m127The Cloud Audit Loggingadvanced6m128TLS Certificates And Chains Of Trustadvanced5m129Insecure Deserializationadvanced5m130WebAuthn And Passkeysadvanced6m131Time Of Check To Time Of Use Racesadvanced6m132Nonce Reuse Dangersadvanced5m133JWT Signature Verification Pitfallsadvanced5m134The Supply Chain Security SBOMadvanced6m135The Padding Oracle Attackadvanced5m136Incident Response Basicsadvanced6m137Secure Session Managementadvanced6m138Supply Chain Attacksadvanced6m139Envelope Encryptionadvanced6m140Business Logic Flaw Reviewadvanced6m141Rate Limiting and Account Lockout Policyadvanced5m142The Threat Modeling Processadvanced6m143The Forward Secrecy In Practiceadvanced5m144The Infrastructure as Code Scanningadvanced6m145HTTP Request Smugglingadvanced6m146The Secure Software Development Lifecycleadvanced6m