A code-level tour of the authentication, authorisation and session weaknesses that recur across the CWE Top 25: improper authentication, missing authentication for a critical function, insufficiently protected credentials, missing and incorrect authorization, improper privilege management, cross-site request forgery, session fixation, insufficient session expiration and weak password recovery mechanisms. Each weakness gets an original vulnerable and fixed example, the detection method that actually catches it, and the safer construct that removes the class, closing with a layered detection strategy and a cross-reference to the published OWASP courses.
Nothing. Every course, exam, and certificate on the catalog is free — including retakes. All you need is a free Safeguard account.
None. The flagship course, Safeguard Certified Practitioner, is a beginner-level course — basic familiarity with how software is built helps, but every exam question is answerable from the lessons themselves.
You can retake it after a 24-hour cooldown, as many times as you need. Retakes are free, and each attempt draws a fresh random set of questions.
The Safeguard Certified Practitioner credential is valid for 24 months from issue. The expiry date is printed on the certificate and shown live on its public verification page. Renewing means passing the current exam again.