Breaking Down Secure Coding
This lecture is designed to be easily understood even if you have no prior knowledge of Secure Coding. After covering fundamental secure coding concepts, it focuses on web service security. This course was originally conducted as a special lecture hosted by OO University. It provides over 160 source codes with extensive comments, pinpointing core topics and techniques that can be applied immediately in the field.
102 learners
Level Intermediate
Course period Unlimited
News
3 articles
# Lecture 11. Breaking Down Secure Coding ## New Lesson Posting Announcement Hello, students! For this course, **393** new lessons (totaling 24 sections) are scheduled to be posted sequentially. Since I am producing multiple courses simultaneously, I am proceeding by **alternating between several courses and posting a little at a time**, rather than uploading one entire course all at once. Below are the posting principles and the posting schedule for each section of this course. > Note: The lessons being posted now are not entirely new content, but are part of the production of **revised editions (2nd or 3rd editions)** that reinforce existing lectures. ## Posting Principles - Currently, I am rotating through a total of 19 courses in order (circular method), posting one lesson per course alternately. - Postings take place on weekdays (Mon-Fri), and a total of 5 new lessons across all courses are uploaded per day. - For this course as well, the next lesson will be posted each time its turn in the rotation comes around. - The posting speed may feel slow compared to other courses, but all courses are progressing together in the same manner. ## Posting Schedule by Section (Total 24 Sections) | Section | Number of Lessons | Start Date | End Date | |---|---|---|---| | Section 2. [Secure Coding Overview & Basics] Importance of Secure Coding | 4 | 2026-07-03 | 2026-07-20 | | Section 3. [Secure Coding Overview & Basics] Threat Modeling | 6 | 2026-07-24 | 2026-08-20 | | Section 4. [Secure Coding Overview & Basics] Coding Standards and Guidelines | 3 | 2026-08-26 | 2026-09-04 | | Section 5. [Secure Coding Overview & Basics] Basic Practice - Secure Input Handling | 4 | 2026-09-10 | 2026-09-25 | | Section 6. [Security Vulnerabilities & Countermeasures by Language] Overview of Security Vulnerabilities by Language | 29 | 2026-10-01 | 2027-02-19 | | Section 7. [Security Vulnerabilities & Countermeasures by Language] Secure Coding in C and C++ | 20 | 2027-02-24 | 2027-05-11 | | Section 8. [Security Vulnerabilities & Countermeasures by Language] Java Secure Coding | 18 | 2027-05-14 | 2027-07-15 | | Section 9. [Security Vulnerabilities & Countermeasures by Language] Python Secure Coding | 19 | 2027-07-20 | 2027-09-10 | | Section 10. [Web Application Security] Application Security Overview | 3 | 2027-09-14 | 2027-09-20 | | Section 11. [Web Application Security] Cross-Site Scripting (XSS) | 22 | 2027-09-22 | 2027-11-19 | | Section 12. [Web Application Security] Cross-Site Request Forgery (CSRF) | 20 | 2027-11-23 | 2028-01-07 | | Section 13. [Web Application Security] Security Headers and HTTPS | 17 | 2028-01-11 | 2028-02-16 | | Section 14. [Authentication and Authorization] Basics of Authentication and Authorization | 19 | 2028-02-17 | 2028-03-27 | | Section 15. [Authentication and Authorization] Password Management | 12 | 2028-03-29 | 2028-04-19 | | Section 16. [Authentication and Authorization] OAuth and JWT | 20 | 2028-04-20 | 2028-05-29 | | Section 17. [Authentication and Authorization] Session Management | 14 | 2028-05-30 | 2028-06-23 | | Section 18. [Practical Application & Analysis of Secure Coding] Code Review and Static Analysis Tools | 4 | 2028-06-26 | 2028-06-29 | | Section 19. [Practical Application & Analysis of Secure Coding] Dynamic Analysis and Pentesting | 14 | 2028-06-30 | 2028-07-19 | | Section 20. [Web Application Security] SQL Injection and Injection Families | 20 | 2028-07-20 | 2028-08-10 | | Section 21. [Access Control] Access Control Systems and Privilege Escalation Defense | 25 | 2028-08-11 | 2028-09-07 | | Section 22. [Data Protection & Encryption] Symmetric/Asymmetric Encryption and Key Management | 25 | 2028-09-08 | 2028-10-05 | | Section 23. [Supply Chain & Dependency Security] SCA, SBOM, and Package Signing | 25 | 2028-10-06 | 2028-11-02 | | Section 24. [API & Cloud Security] OWASP API Top 10, SSRF, and Cloud Isolation | 25 | 2028-11-03 | 2028-11-30 | | Section 25. [Observability, Auditing, & Incident Response] A09 Logging, Monitoring, and IR | 25 | 2028-11-30 | 2028-12-14 | ## Estimated Completion Based on the current pace, the entire course is expected to be fully posted around **December 2028**. (The actual schedule may be moved up or delayed depending on production progress.)At the request of our readers, we are issuing a 66% discount coupon for "Cognitive Load Management Techniques to Break Through the Limits of RAG Performance" (the 990,000 KRW course can be purchased for 330,000 KRW).
For your information, this course is currently in the process of posting the 2nd edition, which is a revision of the 1st edition.
In the case of the 2nd edition, all class materials have been posted, but the videos are still in the process of being uploaded.
I post the 2nd edition videos frequently, but it will take a long time (at least several months) to post all of them.
Please keep this in mind and carefully decide whether to use the coupon.
The deadline is the 19th and there is a limited number of coupons available, so please hurry if you need one.
You can download the coupon by entering the address below into your browser's search bar.
Hello.
The era of AI writing code has arrived.
However, the task of verifying the code written by AI and directing the path for improvement remains the responsibility of humans.
Furthermore, it has become necessary to know how to utilize AI more extensively in both vertical and horizontal directions.
The horizontal direction refers to a direction that encompasses everything from planning to deployment, and
The vertical direction refers to a direction that can encompass various languages, various frameworks, and various methodologies.
Therefore, a developer with a broad spectrum (that is, a complete spectrum in both vertical and horizontal directions)
will be needed.
However, the education system has not yet been able to keep up with this.
That is why I have opened the "Structural Code Reading Bootcamp" using Claude Code.
At https://code-reading-bootcamp.vercel.app/, you can develop the ability to read code written by both AI and humans, and
You will be able to develop the ability to guide AI on how to improve code.
It includes gamification elements, so you can have fun while tracking your skill improvements.
It is free to use anytime without the need to log in.
Although there are some shortcomings and parts where the questions have not yet been filled in,
I introduce this with the hope that it will be helpful to you.
I would appreciate it if you could use it lightly.
February 10, 2026, Sincerely, Jinsu Park (Arigaram).

