Bypassing Content Security Policy in Modern Web Applications

所在平台: Udemy

课程主页: https://www.udemy.com/course/bypassing-content-security-policy-in-modern-web-applications/

课程评论:没有评论

第一个写评论        关注课程

课程简介

课程名称:绕过现代 веб应用程序中的内容安全策略 课程概述:内容安全策略(CSP)是现代 веб 应用程序中最强大的防御技术之一。对于黑客来说,这是一个阻碍他们攻击的障碍。因此,黑客对于绕过内容安全策略尤为关注,而这正是我们希望防止的。在本课程中,您将学习黑客如何能够绕过您的内容安全策略。此外,您还将了解如何检查您的内容安全策略是否容易受到这些攻击。课程内容包括: 1. 黑客如何通过 ajax(dot)googleapis(dot)com 绕过 CSP 的示范。 2. 黑客如何通过 Flash 文件绕过 CSP 的示范。 3. 理解什么是多格式文件(polyglot file),以及它如何被用来绕过 CSP。 4. 黑客如何通过 AngularJS 绕过 CSP 的示范。 每一种攻击都有演示,您可以逐步观看这些攻击在实践中的运作方式。期待在课程中与您见面!

课程评论(0条)

课程详情

Content Security Policy (CSP) is the most powerful defensive technology in modern web applications. For hackers, this is an obstacle that blocks their attacks. That's why hackers are very interested in bypassing Content Security Policy and obviously you don't want that to happen.In this course, you'll learn how your Content Security Policy can be bypassed by hackers. What's more, you'll learn how to check if your Content Security Policy is vulnerable to these attacks. First, I'll show you how hackers can bypass a CSP via ajax(dot)googleapis(dot)com. Next, I'll present how hackers can bypass a CSP via Flash file. After that, I'll explain to you what a polyglot file is and how it can be used to bypass a CSP. Finally, I'll present how hackers can bypass a CSP via AngularJS.------------------------*** For every single attack presented in this course there is a DEMO *** so that you can see step by step how these attacks work in practice. I hope this sounds good to you and I can't wait to see you in the class.------------------------Case #1: Bypassing CSP via ajax(dot)googleapis(dot)comCase #2: Bypassing CSP via Flash FileCase #3: Bypassing CSP via Polyglot FileCase #4: Bypassing CSP via AngularJS

课程标签

0人关注该课程

主题相关的课程