Burp Web Security Academy - Practitioner Labs Walkthrough

所在平台: Udemy

课程主页: https://www.udemy.com/course/burp-suite-practitioner-web-app-penetration-testing-course/

课程评论:没有评论

第一个写评论        关注课程

课程简介

课程名称:Burp Web Security Academy - 实践实验室 walkthrough 课程概述:欢迎参加 Burp Suite Professional - Web 应用渗透测试与漏洞赏金猎人培训课程。请注意,此课程不教授 Burp Suite 的实际使用和功能,而是通过详细讲解提供实践实验室的逐步指导,帮助学员发现和利用网络应用漏洞。 课程讲师马丁·费尔克(Martin Voelk)是一位拥有 25 年网络安全经验的专家,持有多项高级认证,包括 CISSP、OSCP、OSWP、Portswigger BSCP、CCIE、PCI ISA 和 PCIP。他在一家大型科技公司的咨询工作中,参与漏洞赏金项目,发现了成千上万的关键和高危漏洞。 课程内容包括当前所有的 145 个实践实验室,马丁将逐一讲解并解析如何发现和利用这些漏洞。他不仅直接插入有效载荷,还详细说明了每一步的漏洞查找过程及其可被利用的原因。视频内容易于跟随并复制,马丁还分享了许多技巧和窍门,帮助学员获得 Burp Suite Certified Practitioner 认证(BSCP)。 此课程尤其适合希望在 Web 应用渗透测试、漏洞赏金猎人或准备获取 Burp Suite Certified Practitioner 认证(BSCP)的人士。实验室内容涵盖以下主题: - SQL 注入 - 跨站脚本攻击(XSS) - 跨站请求伪造(CSRF) - 点击劫持 - 基于 DOM 的漏洞 - 跨域资源共享(CORS) - XML 外部实体(XXE)注入 - 服务器端请求伪造(SSRF) - HTTP 请求走私 - OS 命令注入 - 服务器端模板注入 - 目录遍历 - 访问控制漏洞 - 认证 - WebSockets - Web 缓存中毒 - 不安全的反序列化 - 信息泄露 - 业务逻辑漏洞 - HTTP 主机头攻击 - OAuth 认证 - 文件上传漏洞 - JWT - 基本技能 - 原型污染 - GraphQL API 漏洞 - 竞争条件 - NoSQL 注入 - API 测试 - Web LLM 攻击 - Web 缓存欺骗 - 无提示的神秘实验室(如考试时解决) 注意与免责声明:Portswigger 实验室是 Portswigger 提供的公共免费服务,任何人都可以使用,以提升技能。只需注册一个免费账户即可。马丁将根据新实验室的发布更新课程,并合理时间内回复问题。学习 Web 应用渗透测试或漏洞赏金猎猎是一个漫长的过程,不必因为未能立即找到漏洞而感到沮丧。请尝试使用 Google,阅读 Hacker One 报告,并深入研究每个功能。此课程仅供教育目的,信息不得用于恶意利用,必须仅在拥有攻击权限的目标上使用。

课程评论(0条)

课程详情

Burp Suite Professional Labs - Web Application Penetration Testing & Bug Bounty HuntingWelcome to the Burp Suite Professional - Web Application Penetration Testing & Bug Bounty Hunting training course.Important note: This course is NOT teaching the actual usage of Burp Suite and its features. This course is proving a step-by-step walkthrough through the practitioner labs with detailed explanations on how to find and exploit web app vulnerabilities.Your instructor is Martin Voelk. He is a Cyber Security veteran with 25 years of experience. Martin holds some of the highest certification incl. CISSP, OSCP, OSWP, Portswigger BSCP, CCIE, PCI ISA and PCIP. He works as a consultant for a big tech company and engages in Bug Bounty programs where he found thousands of critical and high vulnerabilities.This course features all current 145+ Practitioner labs. Martin is solving them all and giving useful insight on how to find and exploit these vulnerabilities. He is not just inserting the payload but explains each step on finding the vulnerability and why it can be exploited in a certain way. The videos are easy to follow along and replicate. Martin is also dropping a lot of tips and tricks for those who wish to get the Burp Suite Certified Practitioner certification (BSCP). This training is highly recommended for anyone who wants to become a professional in Web Application Penetration Testing, Web Application Bug Bounty Hunting or take the Burp Suite Certified Practitioner certification (BSCP) certification.It will feature all Practitioner Labs in the following sections:· SQL injection· Cross-site scripting· Cross-site request forgery (CSRF)· Clickjacking· DOM-based vulnerabilities· Cross-origin resource sharing (CORS)· XML external entity (XXE) injection· Server-side request forgery (SSRF)· HTTP request smuggling· OS command injection· Server-side template injection· Directory traversal· Access control vulnerabilities· Authentication· WebSockets· Web cache poisoning· Insecure deserialization· Information disclosure· Business logic vulnerabilities· HTTP Host header attacks· OAuth authentication· File upload vulnerabilities· JWT· Essential skills· Prototype pollution· GraphQL API vulnerabilities· Race conditions· NoSQL injection· API testing· Web LLM attacks· Web Cache Deception· Mystery Labs without hints (solving like in the exam)Notes & DisclaimerPortswigger labs are a public and a free service from Portswigger for anyone to use to sharpen their skills. All you need is to sign up for a free account. I will update this course with new labs as they are published. I will to respond to questions in a reasonable time frame. Learning Web Application Pen Testing / Bug Bounty Hunting is a lengthy process, so please don't feel frustrated if you don't find a bug right away. Try to use Google, read Hacker One reports and research each feature in-depth. This course is for educational purposes only. This information is not to be used for malicious exploitation and must only be used on targets you have permission to attack.

课程标签

0人关注该课程

主题相关的课程