|
所在平台: Udemy |
课程主页: https://www.udemy.com/course/bug-bounty-fallos-de-seguridad-reales-y-faciles-de-detectar/
课程评论:没有评论
**课程名称:** Bug Bounty- Easy & Real Bugs - Hacking web **课程概述:** 本课程旨在教授学员如何通过每周投入少量时间,在Bug Bounty平台上发现易于检测且报酬丰厚的安全漏洞。讲师分享了自己发现数百个安全漏洞的实战经验,强调手动挖掘漏洞的重要性,并指出无需花费大量时间。课程采用实践和手动挖掘的方法,将通过真实案例演示,并在专门为本课程设计的网站上复现漏洞,提供不同于现有靶场平台的学习体验。 **课程内容亮点:** * **易于发现的漏洞类型:** 重点讲解最容易检测的安全漏洞。 * **实战案例演示:** 展示真实的漏洞发现过程,并在专门设计的网站上进行复现。 * **手动挖掘技巧:** 教授利用手动方法发现漏洞,而非依赖自动化工具。 * **多种漏洞利用技术:** 学习并实践以下漏洞的检测与利用: * IDOR (不安全的直接对象引用) * HTML 注入 * XSS (跨站脚本攻击) * CSRF (跨站请求伪造) * 业务逻辑漏洞 * Open Redirect (开放重定向) * Race Condition (竞态条件) * **实际操作练习:** 提供在线实验室进行练习,并学习Bug Bountyer常用的工具。 **课程目标:** 帮助学员掌握发现Web安全漏洞的实用技巧,提升在Bug Bounty项目中的收入和成功率。
I started practicing Bug Bounty very few hours a week, little by little I noticed that there were many security flaws that you can discover in minutes and that were very well rewarded.In this course I will teach you which are the easiest security flaws to detect. Thanks to these techniques I have been able to report hundreds of security flaws on different Bug Bounty platforms and over the course of this career I have noticed that it is not necessary to spend endless hours in front of the computer to discover a security flaw. Additionally, I have also discovered that a reward is always earned when you find bugs manually and not with automated tools, which is where most people decide to attack. This course has a practical and manual approach.Additionally, I will show you real cases found which I have replicated on a website developed especially for this course, so this course offers different learning than the vulnerable platforms that we already know and have the same security flaws.In this course we will briefly cover an explanation of each exploitation technique followed by a demonstration of vulnerability detection and exploitation. You can learn to exploit:IDORHTML InjectionsXSSCSRFBusiness logicOpenredirectRace ConditionAdditionally, you will be able to put learning into practice with laboratories from the Internet, you will learn to use the most typical tools used by bug hunters.I hope this course is very useful to you and see you!