applied security conferences and training: CanSecWest | PacSec | EUSecWest | BA-Con

Security Masters Dojo

Advanced and intermediate security training and technology enhancement for information security professionals.

CanSecWest: Security Masters Dojo Vancouver

Next Session Dates: March 22-23 2010
Venue: Sheraton Wall Center
Vancouver, Canada
Duration: 1 or 2 Day Courses.
Sessions begin at 10:00 a.m. and go to 6 p.m.
Registration
Maximum:
15 Students per course session.

Advanced PHP Hacking

Instructor:
Laurent Oudot

Register for this course.

Description

Advanced PHP Hacking... Lot of people think they already know everything related to PHP and IT Security, because tons of tiny papers/exploits were released everywhere those years. Some just think that PHP should not be used, but the reality shows that it's a worldwide web language used either by individuals or by corporate teams (Facebook...).

Trying to cover large scale knowledge related to PHP and hacking is not that easy, because it deals with networks, systems, services, applications, code, end-users... Thanks to this training, you'll learn every needed concepts to become a master at PHP Security thanks to the lectures, and you'll also master practical issues thanks to the lab hands-on exercises.

PREREQUISITE WARNING Each class has prerequisites for software loads and a laptop is mandatory. These individual class guides will list material the students are expected have knowledge about coming in and software tools that need to be pre-installed before attending so you get the maximum benefit from the focused intermediate or advanced level course. Please pay particular attention to the prerequisites, as the material listed there will not be reviewed in the courses, and will be necessary to get the maximum benefit out of these educational programs.

After this session, you will really know how attackers work and move through PHP hax0ring so that they can jump downto your networks. Pentesters or security staff will be able to improve their tools and methods. Sysadmins and network staff will be able to help at protecting their information system and at detecting evil behaviors. Of course, developers will avoid errors that might cost a lot.

Topics

Breaking into PHP environment:

Attack Activities:

Defense:

Hacking Simulation:

Prerequisites

Prerequisite material