Free through lesson 3

Python Security for Beginners

From where the ethical and legal lines sit through sockets, HTTP, hashing and encryption, and log analysis, all the way to defending against SQL injection, XSS and CSRF. Thirty lessons that take you to the point where you understand attacks well enough to defend against them. Everything you touch stays inside a practice environment on your own machine (localhost).

Curriculum

The 30 lessons are grouped into six chapters. Working through them in order is the best way, but you are welcome to dip into whatever interests you. Note: lessons that use only the standard library run in the browser as they are. For lessons using sockets, Flask or third-party libraries, use the virtual environment you create in lesson 2.

Chapter 1 — Getting started (lessons 1–3)

You decide up front what is and is not acceptable, and prepare a practice environment (a local lab) that never reaches the outside world. You also revisit the Python you will use throughout, in a security context.

Chapter 2 — Networking (lessons 4–9)

You open TCP connections with sockets and stand up your own server, so "the port is open" stops being an abstraction. You handle HTTP with requests, and finish with the etiquette and the law around scraping.

Chapter 3 — Data and cryptography (lessons 10–13)

You learn to tell encoding, hashing and encryption apart and pick the right one. Tamper detection, storing passwords safely, and encryption with keys.

Chapter 4 — Logs and detection (lessons 14–18)

You break access logs apart with regular expressions and aggregate them to find suspicious signs. You finish by assembling a small intrusion detection routine that combines several rules.

Chapter 5 — Defending the web (lessons 19–24)

You stand up a practice app in Flask, safely reproduce SQL injection, XSS and CSRF, and learn how to stop each of them. Finally you draw out the principle behind all of it: never trust input.

Chapter 6 — Practical tools and wrapping up (lessons 25–30)

You build password strength checking, breach lookups, and certificate and uptime monitoring, then pull them into one checker. Finally you cover how to write a report, where to go next, and the legal and ethical ground rules.

Once you have finished all 30 lessons, build the thing you are defending in Django, or get to know the server side in Linux. Membership unlocks every course.