|
所在平台: Udemy |
课程主页: https://www.udemy.com/course/case-studies-of-award-winning-xss-attacks-part-2/
课程评论:没有评论
课程名称:获奖XSS攻击案例研究:第二部分 **课程概述:** 本课程是“获奖XSS攻击案例研究:第一部分”的延续。我们将继续XSS挖掘之旅,学习更多关于获奖XSS攻击的知识。并非所有XSS猎人都能够成功获得高额奖励,秘诀在于关注“非标准XSS”。本课程将侧重于讲解这些非标准XSS攻击。 讲师是HackerOne平台上的顶级黑客之一,经验丰富,深知如何从XSS漏洞中获利。如果你想成为一名成功的XSS猎人,本课程将为你提供指导。 **本课程将涵盖以下非标准XSS攻击:** 1. 通过XML进行的XSS攻击 2. 通过`location.href`进行的XSS攻击 3. 通过`vbscript`进行的XSS攻击 4. 从XSS到远程代码执行 (RCE) **课程特色:** * **实战演练 (DEMO):** 每个案例都提供演示,循序渐进地展示如何发现这些漏洞。 * **高价值内容:** 专注于能够带来高额奖励的非标准XSS攻击。 **适合人群:** * 希望成为成功的XSS猎人者 * 对网络安全和漏洞挖掘感兴趣者 **推荐:** 如果您对更多获奖XSS攻击案例感兴趣,建议同时学习“获奖XSS攻击案例研究:第一部分”。
This course is the follow-up to one of my previous courses - "Case-Studies of Award-Winning XSS Attacks: Part 1". We will continue our XSS hunting journey and you will learn more about award-winning XSS attacks.There are many people hunting for XSSs, but only a few of them are successful and earn a 4‑digit ($$$$) reward per single XSS. What makes them successful? They focus on non‑standard XSSs and this is exactly what I present in this course!I'm one of the top hackers at HackerOne (among more than 100,000 registered hackers), and I really know how to make money out there. If you want to become a successful XSS hunter, then this course is just for you.In Part 2 of Case-Studies of Award-Winning XSS Attacks, you will learn about the following non-standard XSS attacks:1. XSS via XML2. XSS via location.href3. XSS via vbscript:4. From XSS to Remote Code ExecutionFor every single bug there is a DEMO so that you can see how to find these bugs step-by-step in practice.Do you want to become a successful XSS hunter? Let's enroll to this course and continue our exciting journey. If you are interested in more award-winning XSS attacks, then I also recommend you to see the course "Case-Studies of Award-Winning XSS Attacks: Part 1".