Course Overview

Cross-site scripting (XSS) is one of the most persistent and dangerous web application vulnerabilities, often exploited to steal data, hijack sessions, or deface websites. To combat this, Content Security Policy (CSP) offers a powerful browser feature that allows developers to control the resources a web page is allowed to load and execute. This course is designed to equip security professionals and developers with practical knowledge of CSP, helping them understand how to effectively defend against XSS attacks and enhance their web application security.

This course begins with an introduction to XSS and demonstrates how to build a test site to explore attacks and mitigation techniques. You’ll learn the fundamentals of CSP, its structure, and how to apply it in a Node.js environment. The next chapter covers basic CSP directives, including fetch, document, navigation, and reporting directives. You’ll then dive into advanced CSP attributes like script-src, child-src, connect-src, and sandboxing. The course continues with hands-on demonstrations of CSP use cases for XSS protection, including the use of hashes, nonces, and writing CSPs for single-page applications. Real-world implementations from Google and GitHub are explored, along with frame-based attack mitigation. Finally, advanced concepts like Report-to, report-only mode, CSP Level 3, meta tags, and the transition to HTTPS are discussed in detail.

By the end of this course, you’ll be able to design, test, and implement effective CSPs to secure your web applications against XSS and related threats.

What You Will Learn

  • What a Content Security Policy (CSP) is
  • When you should and should not use a CSP
  • How to create and test a basic CSP
  • Various methods for preventing code injection attacks with CSP

Program Curriculum

  • What Is Cross-site Scripting?
  • Building an XSS Test Site
  • How Does CSP Work?
  • How to Use CSP with Node.js?
  • $7 Million Cybersecurity Scholarship by EC-Council
  • Chapter 1 Quiz

  • Fetch Directives
  • Document Directives
  • Navigation Directives
  • Reporting Directives
  • Chapter 2 Quiz

  • Blocking Inline Scripts
  • The script-src Directive
  • The child-src Directive
  • The connect-src Directive
  • The image-src Directive
  • The media-src Directive
  • Sandboxing
  • Chapter 3 Quiz

  • Writing CSPs for XSS Protection
  • Hashes - Demo
  • Nonces - Demo
  • Writing CSPs for Single Page Applications
  • Implementing a CSP
  • Google’s CSP Methodology
  • GitHub’s CSP Implementation
  • Frame-based Attacks
  • CSP to Prevent Frame-based Attacks

  • The Report-to Directive
  • The Report-only Mode
  • CSP Level 3 Updates
  • CSP in Meta Tags
  • Alternative URL Types
  • Further Directive Types
  • Migrating from HTTP to HTTPS
  • Next Steps in Header Security
  • Chapter 5 Quiz
Load more modules

Instructor

Scott Cosentino

Scott Cosentino is a developer and teacher who is passionate about learning. He works primarily in software development and computer security. Aside from this, he has taught students a variety of programming-related topics, and he loves to inspire students to be passionate about the topics that he teaches. He has experience in both large classes and one on one teaching. Scott believes that mathematics and computer science can be approachable and fun topics. he tailors his courses so that they are easy to comprehend, with an exploration of what, why, and how of every topic. He understands that these topics are not a spectator sport, so he provides as many examples and practises problems as possible so that the viewer can follow along and learn!

Join over 1 Million professionals from the most renowned Companies in the world!

certificate

Choose the Pro Plan That Fits Your Learning Journey

Invest in your future with flexible Pro subscription plans. Whether you're starting your cybersecurity journey or expanding your expertise, choose the membership duration that works for you and gain access to our complete learning platform.

Monthly Plans
Annual Plans
Save 20% with our annual plans!

Pro

Ideal for continuous learning, offering extensive resources with 900+ courses and diverse Learning Paths to enhance your skills.

$ 599.00
Billed annually or $69.00 billed monthly

What is included

  • Access to 900+ Premium Short Courses
  • 70+ Structured Learning Paths
  • Validation of Completion with All Courses and Learning Paths
  • New Courses Added Every Month
Early Access Offer

Pro +

Experience immersive learning with Practice Labs and CTF Challenges for comprehensive skill-building.

$ 699.00
Billed annually or $79.00 billed monthly

Everything in Pro and

  • 500+ Practice Labs with Guided Instructions
  • 400+ CTF Challenges with Detailed Walkthroughs
  • New Practice Labs and Challenges Added Every Month

Related Courses

1 of 50