Hacking and Patching

所在平台: CourseraArchive

课程类别: 其他类别

大学或机构: CourseraNew

课程主页: https://www.coursera.org/archive/hacking-patching

课程评论:没有评论

第一个写评论        关注课程

课程简介

University of Colorado System

课程大纲

In this module we will learn how to hack web app with command injection vulnerability with only four characters malicious string. We will learn how to hack web app with database backend with SQL injection vulnerability and potentially show the list of passwords by injecting string to overwrite SQL query. We will learn how to perform code review to spot the key statements/their patterns that expose the programs for such injection attacks and learn how to patch them. We will learn how to apply security design pattern to defend injection attacks and enhance web security.

课程评论(0条)

课程详情

In this MOOC, you will learn how to hack web apps with command injection vulnerabilities in a web site of your AWS Linux instance. You will learn how to search valuable information on a typical Linux systems with LAMP services, and deposit and hide Trojans for future exploitation. You will learn how to patch these web apps with input validation using regular expression. You will learn a security design pattern to avoid introducing injection vulnerabilities by input validation and replacing generic system calls with specific function calls. You will learn how to hack web apps with SQL injection vulnerabilities and retrieve user profile information and passwords. You will learn how to patch them with input validation and SQL parameter binding. You will learn the hacking methodology, Nessus tool for scanning vulnerabilities, Kali Linux for penetration testing, and Metasploit Framework for gaining access to vulnerable Windows Systems, deploying keylogger, and perform Remote VNC server injection. You will learn security in memory systems and virtual memory layout, and understand buffer overflow attacks and their defenses. You will learn how to clone a Kali instance with AWS P2 GPU support and perform hashcat password cracking using dictionary attacks and known pattern mask attacks.

黑客和修补程序:在此MOOC中,您将学习如何在AWS Linux实例的网站中利用命令注入漏洞来黑客攻击Web应用程序。您将学习如何在具有LAMP服务的典型Linux系统上搜索有价值的信息,以及如何存储和隐藏特洛伊木马程序以备将来使用。您将学习如何使用正则表达式通过输入验证来修补这些Web应用程序。您将学习一种安全设计模式,以避免通过输入验证和使用特定功能调用替换通用系统调用而引入注入漏洞。您将学习如何使用SQL注入漏洞来入侵Web应用程序以及如何检索用户配置文件信息和密码。您将学习如何使用输入验证和SQL参数绑定来修补它们。您将学习黑客方法,用于扫描漏洞的Nessus工具,用于渗透测试的Kali Linux和用于访问易受攻击的Windows系统,部署键盘记录程序以及执行远程VNC服务器注入的Metasploit Framework。您将学习内存系统和虚拟内存布局中的安全性,并了解缓冲区溢出攻击及其防御措施。您将学习如何克隆具有AWS P2 GPU支持的Kali实例,以及如何使用字典攻击和已知的模式掩码攻击执行哈希猫密码破解。

课程标签

0人关注该课程

主题相关的课程