Exploiting and Securing Vulnerabilities in Java Applications

所在平台: CourseraArchive

课程类别: 其他类别

大学或机构: CourseraNew

课程主页: https://www.coursera.org/archive/exploiting-securing-vulnerabilities-java-applications

课程评论:没有评论

第一个写评论        关注课程

课程大纲

Setup and Introduction to Cross Site Scripting Attacks
Injection Attacks
Authentication and Authorization
Dangers of Vulnerable Components and Final Project

课程评论(0条)

课程详情

In this course, we will wear many hats. With our Attacker Hats on, we will exploit Injection issues that allow us to steal data, exploit Cross Site Scripting issues to compromise a users browser, break authentication to gain access to data and functionality reserved for the ‘Admins’, and even exploit vulnerable components to run our code on a remote server and access some secrets. We will also wear Defender Hats. We will dive deep in the code to fix the root cause of these issues and discuss various mitigation strategies. We do this by exploiting WebGoat, an OWASP project designed to teach penetration testing. WebGoat is a deliberately vulnerable application with many flaws and we take aim at fixing some of these issues. Finally we fix these issues in WebGoat and build our patched binaries. Together we will discuss online resources to help us along and find meaningful ways to give back to the larger Application Security community.

利用和保护Java应用程序中的漏洞:在本课程中,我们会戴着很多帽子。启用“攻击者之帽”后,我们将利用注入问题,使我们能够窃取数据,利用跨站点脚本问题来破坏用户浏览器,破坏身份验证以访问为“管理员”保留的数据和功能,甚至利用易受攻击的组件在远程服务器上运行我们的代码并访问一些机密。我们还将戴上Defender Defender Hats。我们将深入研究代码以解决这些问题的根本原因,并讨论各种缓解策略。我们通过利用WebGoat(一个旨在教授渗透测试的OWASP项目)来实现这一目标。 WebGoat是一个故意易受攻击的应用程序,具有许多缺陷,我们致力于解决其中的一些问题。最后,我们在WebGoat中修复了这些问题,并构建了已修补的二进制文件。我们将一起讨论在线资源,以帮助我们并找到有意义的方法来回馈更大的Application Security社区。

课程标签

0人关注该课程

主题相关的课程