A practitioner course on two related but distinct vulnerability classes that arise from untrusted input reaching a filesystem location or a system shell without adequate control. You will learn how path traversal manipulates a file path to reach a location outside an application's intended directory, why canonicalization followed by base directory verification is the accepted fix rather than blacklist filtering, how command injection lets an attacker's input reach a shell for interpretation with a typically far more severe consequence, why avoiding shell invocation and preferring a structured argument list is the primary defense, and how sandboxing, least-privilege process execution, logging-based detection and a shared code review method close the gap for what remains.
Nothing. Every course, exam, and certificate on the catalog is free — including retakes. All you need is a free Safeguard account.
None. The flagship course, Safeguard Certified Practitioner, is a beginner-level course — basic familiarity with how software is built helps, but every exam question is answerable from the lessons themselves.
You can retake it after a 24-hour cooldown, as many times as you need. Retakes are free, and each attempt draws a fresh random set of questions.
The Safeguard Certified Practitioner credential is valid for 24 months from issue. The expiry date is printed on the certificate and shown live on its public verification page. Renewing means passing the current exam again.