|
所在平台: Udemy |
课程主页: https://www.udemy.com/course/advanced-linux-privilege-escalation-with-hack-the-box/
课程评论:没有评论
**课程名称:** 进阶 Linux 权限提升(Hack The Box) **课程概述:** 本课程(2021年春/夏推出)提供100%动手实践体验,教授攻击者在获取 Linux 服务器初始访问权限后,如何运用相同的技术来提升权限。课程摒弃了传统的“PPT折磨”模式,完全侧重于实战操作。 **目标学员:** 本课程面向中高级用户,旨在帮助他们发现并利用流行的 Linux 服务器配置错误,包括已打补丁的系统,从而实现权限提升。所有技巧都将详细分步讲解,并与 MITRE ATT & CK 对应。 **核心特点:** * **实战驱动:** 强调动手操作,而非理论讲解。 * **深度解析:** 详细解释每种方法的工作原理,以及常见的企业环境配置错误。 * **手动为主:** 尽管会使用 Metasploit,但更侧重于手动攻防技巧的讲解。 * **循序渐进:** 漏洞利用的难度会随着课程进展逐步提升。 * **最新技术:** 涵盖最新的研究成果,如“CVE 修改 Launch Daemon”。 **将学习的技术:** * 恶意 Python 包 * CVE 修改 Launch Daemon (新增!2021 年 2 月 12 日更新 6 个新讲座!) * 以及其他多种权限提升技术,将在5个易受攻击的机器上进行实践。 **将使用的工具:** ffuf, gobuster, dirsearch, nmap, Bash Scripting, Python Scripting, netcat, pwncat, Burp Suite (高级功能),等等。还将学习 SQL 注入检测、服务器端模板注入(SSTI)的利用等。 **学习目标:** 完成课程后,学员应能将所学技术应用于日常工作、OSCP 考试准备以及 CTF 竞赛。 **实验环境:** * **5个易受攻击的机器:** 所有实验环境已在 HackTheBox VIP 实验室预设。 * **无需本地设置:** 合作伙伴 HackTheBox VIP 实验室提供便捷的实验室环境,只需 VPN 连接即可开始,无需配置本地虚拟机。 * **真实性:** 大部分系统经过授权,提供最真实的漏洞利用环境。 **观影提示:** 视频特写放大命令提示符和终端,方便在手机上观看。
New Spring/Summer 2021 Launch!This is a 100% hands on course as you will be using the same tradecraft and techniques Red Teamer's and advanced adversaries use to escalate privileges on Linux servers after they have gained initial access and established a foothold. This course is not "death by PowerPoint", in fact there is not a single Powerpoint slide in the course. This course is aimed for intermediate to advanced users who are hungry to know how to discover and exploit novel escalation paths on popular Linux servers (including some that are patched). Everything is carefully, explained - step-by-step and mapped to MITRE ATT & CKAdditionally, although Metasploit is used in some attacks, we will be using less Metasploit and more manual walk-throughs because I wanted to take the time to carefully explain WHY each method works and detail how common misconfigurations happen in enterprise environments.Where Metasploit is used, everything is carefully explained and deconstructed so you can understand why and how it works. Exploits start easy and escalate in difficulty as you progress through the course.The TechniquesYou will quickly learn and execute the following escalation of privilege techniques across 5 vulnerable machines. New videos are being released weekly.Malicious Python PackageCVE Modify Launch Daemon (NEW! Just added 02/12/2021 6 New Lectures!)The ToolsYou will use ffuf, gobuster, dirsearch, nmap, Bash Scripting, Python Scripting, netcat, pwncat, Burp Suite (advanced features) and more. You will learn how to threat hunt for SQLi attacks and how to exploit Server Side Template Injection (SSTI) attacks and much much more.My dream for youBy the end of this course you should be able to use these techniques in:Your day to day workOSCP preparationCTF hackingAbout the labThere are 5 vulnerable machines.No lab setup is required as the entire environment is already established in HackTheBox VIP labsI wanted to make this course as realistic as possible while removing as many barriers to entry as possible so I've partnered with HackTheBox VIP labs to make it as easy as possible to get started.Yes, HackTheBox is an additional charge but it offers hundreds of pre-configured vulnerable machines in a lab which is accessible via a VPN connection. This means you can get started right away and don't have to waste time fumbling with VirtualBox and VMWare settings on your local system. Most of the systems are also licensed which provides the best environment for realistic exploitation.Tip:I made these videos so all commands are zoomed in close so you can watch on a mobile phone if desired. I hate watching videos on my smartphone and squinting at the command prompt or terminal. Never again will that happen.