|
所在平台: Udemy |
课程主页: https://www.udemy.com/course/burp-suite-apprentice-web-app-penetration-testing-course/
课程评论:没有评论
课程名称:Burp Web Security Academy - Apprentice Labs Walkthrough 概述:欢迎来到Burp Suite Apprentice - 网络应用渗透测试与漏洞赏金猎人培训课程。重要提醒:本课程并不教授Burp Suite的实际使用及其功能,而是提供逐步的实验室实操,通过详细解释指导如何发现和利用网络应用漏洞。课程讲师是网络安全专家Martin Voelk,他拥有25年的丰富经验,持有多项高级认证,包括CISSP、OSCP、OSWP、Portswigger BSCP、CCIE、PCI ISA和PCIP。Martin在一家大型科技公司担任顾问,并积极参与漏洞赏金项目,发现了成千上万的关键和高危漏洞。 课程包含所有当前52个实验室,Martin将逐一解决每个实验室的题目,并提供有效的洞见,帮助学员理解如何找到和利用这些漏洞。他不仅提供有效载荷的插入实例,还解释了发现漏洞的每一步及其可利用的原因。视频内容易于跟随和复现,Martin还分享了许多技巧,适合希望获得Burp Suite认证从业者资格(BSCP)的学员。 本课程强烈推荐给任何想要开始网络应用渗透测试、网络应用漏洞赏金猎人领域的人士,或作为通向Burp Suite认证从业者资格(BSCP)的专业课程的前提条件。课程中将涵盖所有实验室,内容包括但不限于以下主题: - SQL注入 - 跨站脚本攻击 - 跨站请求伪造(CSRF) - 点击劫持 - 跨源资源共享(CORS) - XML外部实体(XXE)注入 - 服务器端请求伪造(SSRF) - 操作系统命令注入 - 目录遍历 - 访问控制漏洞 - 身份验证 - WebSockets - 不安全的反序列化 - 信息泄露 - 商业逻辑漏洞 - HTTP主机头攻击 - OAuth身份验证 - 文件上传漏洞 - JWT - GraphQL API漏洞 - 竞争条件 - NoSQL注入 - API测试 - Web LLM攻击 - Web缓存欺骗 - 学徒神秘实验室 注意事项与免责声明:Portswigger实验室是一项公开的免费服务,任何人都可以注册免费账户进行练习。本课程将随着新实验室的发布而更新,并希望在合理的时间内回答问题。学习网络应用渗透测试/漏洞赏金猎人是一个漫长的过程,请不要因未立即发现漏洞而感到挫败。建议利用Google搜索、阅读Hacker One报告,深入研究每个功能。本课程仅用于教育目的,信息不得用于恶意利用,必须仅在获得攻击目标许可的情况下使用。
Welcome to the Burp Suite Apprentice - Web Application Penetration Testing & Bug Bounty Hunting training course.Important note: This course is NOT teaching the actual usage of Burp Suite and its features. This course is proving a step-by-step walkthrough through the apprentice labs with detailed explanations on how to find and exploit web app vulnerabilities.Your instructor is Martin Voelk. He is a Cyber Security veteran with 25 years of experience. Martin holds some of the highest certification incl. CISSP, OSCP, OSWP, Portswigger BSCP, CCIE, PCI ISA and PCIP. He works as a consultant for a big tech company and engages in Bug Bounty programs where he found thousands of critical and high vulnerabilities.This course features all current 52 Apprentice labs. Martin is solving them all and giving useful insight on how to find and exploit these vulnerabilities. He is not just inserting the payload but explains each step on finding the vulnerability and why it can be exploited in a certain way. The videos are easy to follow along and replicate. Martin is also dropping a lot of tips and tricks for those who wish to get the Burp Suite Certified Practitioner certification (BSCP). This training is highly recommended for anyone who wants to start out in Web Application Penetration Testing, Web Application Bug Bounty Hunting or as a pre-requisite for the Professional course towards the Burp Suite Certified Practitioner certification (BSCP) certification.It will feature all Apprentice Labs in the following sections:· SQL injection· Cross-site scripting· Cross-site request forgery (CSRF)· Clickjacking· Cross-origin resource sharing (CORS)· XML external entity (XXE) injection· Server-side request forgery (SSRF)· OS command injection· Directory traversal· Access control vulnerabilities· Authentication· WebSockets· Insecure deserialization· Information disclosure· Business logic vulnerabilities· HTTP Host header attacks· OAuth authentication· File upload vulnerabilities· JWT· GraphQL API vulnerabilities· Race conditions· NoSQL injection· API testing· Web LLM attacks· Web Cache Deception· Apprentice Mystery LabsNotes & DisclaimerPortswigger labs are a public and a free service from Portswigger for anyone to use to sharpen their skills. All you need is to sign up for a free account. I will update this course with new labs as they are published. I will to respond to questions in a reasonable time frame. Learning Web Application Pen Testing / Bug Bounty Hunting is a lengthy process, so please don't feel frustrated if you don't find a bug right away. Try to use Google, read Hacker One reports and research each feature in-depth. This course is for educational purposes only. This information is not to be used for malicious exploitation and must only be used on targets you have permission to attack.