Home
Learn
Feed
Ladder
Saved
← Paths
🔐
Web Security
Defensive security across the stack — XSS, auth, crypto, and application security.
Curriculum · 146 lessons
01
Authentication vs Authorization
intro
3m
02
Symmetric versus Asymmetric Encryption
intro
4m
03
The IAM Roles and Policies
intro
4m
04
Cross Site Scripting XSS
intro
4m
05
Role Based Access Control
intro
4m
06
The Symmetric Encryption AES
intro
4m
07
Cross Site Request Forgery CSRF
intro
4m
08
Zero Trust Architecture
intro
5m
09
XML External Entity Prevention
intro
4m
10
The TLS Handshake in Depth
intro
5m
11
The OWASP Top Ten Overview
intro
4m
12
The Asymmetric RSA
intro
4m
13
Insecure Direct Object References IDOR
intro
4m
14
HttpOnly And Secure Cookie Flags
intro
4m
15
Path Traversal Prevention
intro
4m
16
The Least Privilege in Cloud
intro
4m
17
The AES Block Cipher
intro
4m
18
The Hashing SHA Family
intro
4m
19
HTTP Security Headers
intro
4m
20
Multi Factor Authentication
intro
4m
21
The Security Headers Checklist
intro
4m
22
Password Spraying Attacks
intro
3m
23
Certificate Pinning
intro
4m
24
The Secrets Manager and KMS
intro
5m
25
Typosquatting In Package Registries
intro
3m
26
Public Object Storage Exposure
intro
3m
27
Coordinated Vulnerability Disclosure
intro
4m
28
HTTP Parameter Pollution
core
4m
29
Step Up Authentication
core
4m
30
Clickjacking and Frame Options
core
4m
31
Secure Cookie Attributes Revisited
core
4m
32
Security Misconfiguration
core
4m
33
Hashing versus Encryption
core
4m
34
VPN and Tunnel Security
core
4m
35
Dependency Vulnerability Scanning
core
5m
36
Host Header Injection
core
4m
37
Rate Limiting as a Defense
core
4m
38
Session Fixation Prevention
core
4m
39
The Principle Of Least Privilege
core
4m
40
Dependency Scanning
core
4m
41
Open Redirect Prevention
core
4m
42
The Man in the Middle Threat Model
core
5m
43
Secrets Management in Apps
core
5m
44
The Salting And Peppering
core
4m
45
Machine To Machine Auth With Client Credentials
core
4m
46
SQL injection & parameterization
core
5m
47
The Path Traversal Attack
core
5m
48
Defense In Depth
core
4m
49
Security Logging and Monitoring
core
5m
50
Same Site Cookies
core
5m
51
Cipher Modes and the Initialization Vector
core
5m
52
DNS Security and DNSSEC
core
5m
53
The HMAC For Integrity
core
4m
54
LDAP Injection
core
4m
55
HMAC Message Authentication
core
4m
56
Network Segmentation
core
4m
57
JSON Web Tokens
core
5m
58
Server Side Request Forgery SSRF
core
5m
59
Command Injection Prevention
core
5m
60
Salting and Peppering Passwords
core
5m
61
SQL Injection Prevention
core
5m
62
The Block Cipher Modes
core
5m
63
The Container Image Scanning
core
5m
64
NoSQL Injection
core
4m
65
OAuth Scopes And Consent
core
5m
66
Logging And Audit Trails
core
5m
67
The Random Number Generator and Entropy
core
5m
68
The CSRF Token Defense
core
5m
69
Secrets Management
core
5m
70
Content Security Policy Headers
core
5m
71
API Authorization Checks
core
5m
72
Key Derivation Functions
core
5m
73
Mutual TLS Authentication
core
5m
74
The Password Hashing Bcrypt Argon2
core
5m
75
The Security Groups and NACLs
core
5m
76
The Pod Security Standards
core
5m
77
Code Signing And Signature Verification
core
4m
78
Subresource Integrity
core
5m
79
Mass Assignment Protection
core
5m
80
The Certificate Chain of Trust
core
5m
81
Cross Site Scripting Types
core
5m
82
The Certificate Authorities
core
5m
83
Password Hashing With bcrypt
core
5m
84
Brute Force and Credential Stuffing Defense
core
5m
85
Attribute Based Access Control
core
5m
86
Server Side Template Injection Defense
core
5m
87
Single Sign On with SAML
core
5m
88
The Elliptic Curve Crypto
core
5m
89
The VPC Isolation Security
core
5m
90
The OAuth Device Authorization Flow
core
5m
91
Regular Expression Denial Of Service Prevention
core
5m
92
Authenticated Encryption with GCM
core
5m
93
Key Rotation
core
5m
94
OpenID Connect
core
5m
95
The Runtime Container Security
core
5m
96
Protocol Downgrade Attacks
core
4m
97
Refresh Token Rotation
core
5m
98
Prototype Pollution Defense
core
5m
99
Digital Signatures
core
5m
100
The Kubernetes RBAC
core
5m
101
Security Of File Uploads
core
6m
102
Server Side Request Forgery
core
5m
103
The Key Derivation Functions
core
5m
104
Dependency Confusion Attacks
core
4m
105
The OAuth Authorization Code Flow
core
6m
106
The Network Policies in Kubernetes
core
5m
107
The PKCE Extension
core
6m
108
The Compliance and Benchmarks CIS
core
5m
109
Hardware Security Modules
core
4m
110
Protecting The Cloud Metadata Service
core
4m
111
Rotating Signing Keys With JWKS
advanced
5m
112
Restricting Syscalls With Seccomp
advanced
5m
113
DNS Rebinding
advanced
5m
114
Log4Shell And JNDI Injection
advanced
5m
115
Timing Side Channel Attacks
advanced
5m
116
Encryption At Rest Vs In Transit
advanced
5m
117
Elliptic Curve Cryptography Basics
advanced
5m
118
Web Cache Poisoning
advanced
5m
119
Token Introspection and Revocation
advanced
5m
120
Threat Modeling Basics
advanced
5m
121
Secure Defaults And Hardening
advanced
5m
122
Constant Time Comparison
advanced
5m
123
The Digital Signatures
advanced
5m
124
Input Validation And Allowlists
advanced
5m
125
Dependency And Supply Chain Hygiene
advanced
6m
126
The Random Number Generation Crypto
advanced
5m
127
The Cloud Audit Logging
advanced
6m
128
TLS Certificates And Chains Of Trust
advanced
5m
129
Insecure Deserialization
advanced
5m
130
WebAuthn And Passkeys
advanced
6m
131
Time Of Check To Time Of Use Races
advanced
6m
132
Nonce Reuse Dangers
advanced
5m
133
JWT Signature Verification Pitfalls
advanced
5m
134
The Supply Chain Security SBOM
advanced
6m
135
The Padding Oracle Attack
advanced
5m
136
Incident Response Basics
advanced
6m
137
Secure Session Management
advanced
6m
138
Supply Chain Attacks
advanced
6m
139
Envelope Encryption
advanced
6m
140
Business Logic Flaw Review
advanced
6m
141
Rate Limiting and Account Lockout Policy
advanced
5m
142
The Threat Modeling Process
advanced
6m
143
The Forward Secrecy In Practice
advanced
5m
144
The Infrastructure as Code Scanning
advanced
6m
145
HTTP Request Smuggling
advanced
6m
146
The Secure Software Development Lifecycle
advanced
6m