Hacking and Patching

所在平台: Coursera

课程主页: https://www.coursera.org/learn/hacking-patching

课程评论:没有评论

第一个写评论        关注课程

课程简介

课程名称:黑客与修补 概述:在这门大型在线开放课程(MOOC)中,您将学习如何利用命令注入漏洞对AWS Linux实例上的网页应用进行攻击。您将掌握如何在典型的Linux系统上使用LAMP服务搜索有价值的信息,并存放和隐藏特洛伊木马以便将来利用。您还将学习如何通过使用正则表达式进行输入验证来修补这些网页应用,避免引入注入漏洞的安全设计模式,并用特定函数替换通用系统调用。此外,您还将学习如何利用SQL注入漏洞对网页应用进行攻击,获取用户个人资料和密码,并通过输入验证和SQL参数绑定来进行修补。课程将介绍黑客方法论、Nessus漏洞扫描工具、Kali Linux渗透测试以及Metasploit框架,帮助您获得对脆弱Windows系统的访问权限,部署记录键盘输入的程序以及执行远程VNC服务器注入。您将了解内存系统的安全性、虚拟内存布局,掌握缓冲区溢出攻击及其防御。此外,您还将学习如何使用带有AWS P2 GPU支持的Kali实例克隆、执行hashcat密码破解,使用字典攻击和已知模式掩码攻击。 课程大纲: 1. 注入网络应用攻击及其防御:学习如何用四个字符的恶意字符串进行命令注入攻击,利用SQL注入漏洞通过注入字符串来修改SQL查询,并查看密码列表。还将进行代码审查以查找暴露在此类注入攻击中的关键语句及其模式,并学习如何进行修补以及应用安全设计模式以增强网络安全。 2. 黑客SQL数据库并修补SQL注入漏洞的网页应用:探讨如何利用SQL注入漏洞攻击有数据库后端的网页应用,潜在地通过注入字符串来查看密码列表,并进行代码审查以确定漏洞关键语句。学习八步黑客方法论以及如何利用命令注入漏洞搜索文件系统并存放/隐藏特洛伊木马以便将来利用。 3. 内存攻击与防御:了解现代操作系统提供的典型保护机制,以防止进程访问属于其他进程的数据。学习缓冲区溢出攻击及其常见防御措施。 4. 渗透测试:学习如何使用Nessus工具进行漏洞扫描,掌握利用Kali Linux中包含的工具进行渗透测试,以及如何使用Metasploit框架控制脆弱的机器,部署键盘记录器,实现远程Shell和远程VNC注入。同时学习如何从Ubuntu镜像克隆AWS P2.xlarge GPU实例,并使用hashcat软件破解密码。

课程大纲

Name:Injection Web App Attacks and Their Defenses

Description: In this module we will learn how to hack web app with command injection vulnerability with only four characters malicious string. We will learn how to hack web app with database backend with SQL injection vulnerability and potentially show the list of passwords by injecting string to overwrite SQL query. We will learn how to perform code review to spot the key statements/their patterns that expose the programs for such injection attacks and learn how to patch them. We will learn how to apply security design pattern to defend injection attacks and enhance web security.

Name:Hack SQL Databases and Patch Web Apps with SQL Injection Vulnerabilities

Description:In this module we will learn how to hack web app with database backend with SQL injection vulnerability and potentially show the list of passwords by injecting string to overwrite SQL query.We will learn how to perform code review to spot the key statements/their patterns that expose the programs for such injection attacks and learn how to patch them. We will learn the eight-step hacker methodology for exploit systems. For the escalating privilege techniques, we show how to leverage command injection vulnerability to search file systems and deposit/hide Trojans for future exploit.

Name:Memory Attacks and Defenses

Description:In this module, we learn about the typical protection mechanism provided by the modern OS to prevent process from accessing other pages data belong different process. We will also learn buffer overflow attacks and their common defenses.

Name:Penetration Testing

Description:In this module we will learn how to perform Vulnerability Scanning with Nessus tool, learn to perform penetration testing using tools included in Kali Linux distribution and to use Metasploit Framework to take control a vulnerable machine, deploy keylogger, run remote shell and remote VNC injection. We will also learn how to clone an AWS P2.xlarge GPU instance from a Ubuntu image with hashcat software to crack passwords.

课程评论(0条)

课程详情

In this MOOC, you will learn how to hack web apps with command injection vulnerabilities in a web site of your AWS Linux instance. You will learn how to search valuable information on a typical Linux systems with LAMP services, and deposit and hide Trojans for future exploitation. You will learn how to patch these web apps with input validation using regular expression. You will learn a security design pattern to avoid introducing injection vulnerabilities by input validation and replacing generic system calls with specific function calls. You will learn how to hack web apps with SQL injection vulnerabilities and retrieve user profile information and passwords. You will learn how to patch them with input validation and SQL parameter binding. You will learn the hacking methodology, Nessus tool for scanning vulnerabilities, Kali Linux for penetration testing, and Metasploit Framework for gaining access to vulnerable Windows Systems, deploying keylogger, and perform Remote VNC server injection. You will learn security in memory systems and virtual memory layout, and understand buffer overflow attacks and their defenses. You will learn how to clone a Kali instance with AWS P2 GPU support and perform hashcat password cracking using dictionary attacks and known pattern mask attacks.

课程标签

0人关注该课程

主题相关的课程