A defensive, concept-first course on XML External Entity (XXE) injection and the wider XML security surface it sits inside. You will learn how an XML parser's entity resolution feature creates the vulnerability, where it hides in features that do not look like XML processing, why the real fix is a parser configuration change rather than input filtering, and why modern framework defaults have reduced but not eliminated the risk. The course also covers signature wrapping attacks against signed XML documents, entity expansion resource exhaustion, testing for XXE responsibly during a security review, and how the pattern relates to insecure deserialization, all without ever constructing a working exploit.
Nothing. Every course, exam, and certificate on the catalog is free — including retakes. All you need is a free Safeguard account.
None. The flagship course, Safeguard Certified Practitioner, is a beginner-level course — basic familiarity with how software is built helps, but every exam question is answerable from the lessons themselves.
You can retake it after a 24-hour cooldown, as many times as you need. Retakes are free, and each attempt draws a fresh random set of questions.
The Safeguard Certified Practitioner credential is valid for 24 months from issue. The expiry date is printed on the certificate and shown live on its public verification page. Renewing means passing the current exam again.