|
所在平台: Udemy |
课程主页: https://www.udemy.com/course/android-penetration-testing-using-diva/
课程评论:没有评论
课程名称:Android 渗透测试 课程概述:在本课程中,您将学习 Android 渗透测试的基础知识。通过讲座,您将了解如何开始分析 Android 应用程序,并涵盖脆弱应用 DIVA(Damn Insecure and Vulnerable Application)中的不同漏洞。我们的课程将涵盖以下几个重要领域: 1. 反向工程应用程序以获取源代码。 2. 分析应用程序代码,寻找漏洞。 3. 理解解压和反编译 APK 之间的区别。 4. 在 Kali 虚拟机上捕获手机的浏览器请求并分析流量。 5. 我们将涵盖的漏洞包括: i. 不安全的日志记录 ii. 硬编码问题 iii. 不安全的数据存储 iv. 输入验证问题 v. 访问控制问题 在课程结束时,我们将完成 DIVA 应用的所有 13 个练习,并学习 Android 渗透测试的基本知识。
In this course you will be learning about the basics of android pentesting. Throughout the lectures you will be covering how to start analysing android application and cover different vulnerabilities in the vulnerable application DIVA: Damn Insecure and Vulnerable Application. Lets take a look at some important areas we are going to cover in our course -1. We will reverse the application to get the source code.2. We will be analysing the application code and finding the vulnerability.3. We will understand the difference between unzipping and decompiling an apk.4. We will capture the browser requests of our mobile on the kali vm and analyse the traffic.5. The vulnerabilities we are going to cover are: i. Insecure Logging ii. Hardcoding Issues iii. Insecure Data Storage iv. Input Validation Issue v. Access Control IssueIn the end of of the course we will complete all the 13 exercises of DIVA application and learn the basics of android penetration testing.