Path · 35 hours · 45 lessons
Secure Backend Developer
Backend developers writing safe code. 9 modules, 45 lessons, 15–30 minutes each. Every lesson ends with a patch, not a flag.
Plan · 6 weeks × 5 sessions × 25 min···
Done In progress Needs review
01The risk map and an AppSec mindset4 lessons2.5h
02Access Control6 lessons4hASVS V8
IDOR and how to stop it at the query layerwalkthrough25m
Function-level authorisation (API5)walkthrough25m
Mass assignment and separate input DTOswalkthrough22m
A central authorisation decision pointconcept20m
RLS as a second layer of defencewalkthrough28m
Challenge: patch a BOLA-ridden servicechallenge33m
03Injection & Output Encoding6 lessons4hASVS V1, V2
SQL injection and parameterisationwalkthrough25m
The escape hatches your ORM still leaves openwalkthrough24m
Encoding for the output contextwalkthrough26m
Command injection: do not go through a shellwalkthrough24m
XXE and parser defaultswalkthrough25m
Challenge: four interpreters, one principlechallenge37m
04Authentication & Session6 lessons4.5hASVS V6, V7, V9, V10
Storing passwords, and why you should not store themwalkthrough26m
Verifying a JWT properlywalkthrough28m
Choosing the right OAuth flow for the clientconcept20m
Session lifetime, and what logout actually doeswalkthrough26m
Account enumeration: four channels, not just the error messagewalkthrough25m
Challenge: patch a login flow end to endchallenge37m
05Cryptography & Secrets5 lessons3.5hASVS V11, V14
06Supply Chain & Integrity5 lessons4hASVS V10
07SSRF & calling external APIs4 lessons3hASVS V13
08Logging, Error Handling & Response4 lessons3hASVS V16
09Secure Design & Threat Modeling5 lessons4.5hASVS V1–V17