Android Penetration Testing 101

所在平台: Udemy

课程主页: https://www.udemy.com/course/android-penetration-testing-101/

课程评论:没有评论

第一个写评论        关注课程

课程简介

课程名称:Android渗透测试101 课程概述: Android渗透测试101课程专为初学者设计,旨在帮助对Android安全感兴趣但不知从何入手的人。该课程内容全面,从理解Android架构到利用各种攻击向量分析Android应用程序,涵盖了多个方面。在课程中,您将学习如何对Android应用程序进行静态分析,包括使用React Native、Java、Flutter和Cordova等框架开发的应用程序。课程将介绍一些关键工具,如Jadx、Jeb反编译器和GDA反编译器,以帮助您进行静态分析。此外,还将涵盖自动化扫描器MOBSF的安装和使用,使您能够对应用程序进行动态分析,识别常见漏洞。 动态分析是渗透测试中最有趣的部分之一。在本课程中,您将了解动态分析对移动应用程序的重要性及其在漏洞检测中的作用。课程提供了设置动态分析实验室的逐步指南,介绍如何使用Burp Suite和Genymotion进行动态分析。SSL钉扎是动态分析部分的重要概念,本课程将深入探讨SSL钉扎,并演示如何在Android上绕过各种方法。 为提高您的动态分析技能,课程还引入强大的工具,如Frida和objection,并提供其设置和使用的说明。课程结束时,将进行一次实时动态分析的演示,您将学习如何识别常见漏洞,定位相关端点,并从应用程序的数据库中提取敏感信息。 作为额外福利,课程提供了一份Android渗透测试检查清单,作为实时分析期间的参考指南,确保您在渗透测试时体验更加顺利。

课程评论(0条)

课程详情

The Android Penetration Testing 101 course is designed for beginners who are interested in exploring Android security but don't know where to start. This comprehensive course covers everything from understanding the Android architecture to analyzing Android applications using various attack vectors.Throughout the course, you will learn how to perform static analysis on Android applications, including those developed with frameworks like React Native, Java, Flutter, and Cordova. You'll be introduced to essential tools such as Jadx, Jeb decompiler, and GDA decompiler, which aid in the static analysis process. Additionally, the course covers the installation and usage of automated scanners like MOBSF, enabling you to perform dynamic analysis on apps and identify common vulnerabilities. The course also highlights the key endpoints to focus on during static analysis.One of the most exciting aspects of penetration testing is dynamic analysis. In this course, you'll understand why dynamic analysis is crucial for mobile applications and its role in vulnerability hunting. The course provides a step-by-step guide for setting up a dynamic analysis lab, featuring the use of Burp Suite with Genymotion. SSL pinning is a fundamental concept covered extensively in the dynamic analysis section. The course explores SSL pinning in detail and demonstrates various methods to bypass it on Android.To enhance your dynamic analysis skills, the course introduces powerful tools like Frida and objection, and provides instructions on their setup and usage. The course concludes with a live dynamic analysis session on an Android application, during which you'll learn how to identify common vulnerabilities, locate relevant endpoints, and extract sensitive information from the app's database.As a bonus, the course includes an Android pentesting checklist, which serves as a handy reference guide during real-time analysis, ensuring a smoother pentesting experience.

课程标签

0人关注该课程

主题相关的课程