|
所在平台: Udemy |
课程主页: https://www.udemy.com/course/cross-site-scripting-attack-defense/
课程评论:没有评论
课程名称:跨站脚本攻击与防御 概述:本课程专门设计用于理解跨站脚本漏洞(XSS),并提供全面的实践经验。课程将指导学生建立自己的本地渗透测试环境,以便在安全的环境中进行练习。学生将学习跨站脚本漏洞的基本概念,以及不同类型的XSS是如何工作的。通过攻击方法,学生将深入理解XSS攻击在实际中的发生方式。同时,他们将学习使用不同的漏洞扫描器来查找XSS漏洞。此外,课程还教授如何通过转义用户输入、使用内容安全策略等方法来防止和限制XSS攻击,从而形成防御性的方法,这也正是课程命名为“跨站脚本:攻击与防御”的原因。最后,学生还将学习使用各种备忘单来规避WAF和防火墙,并通过实施安全编码实践和正确处理不受信任的数据来防止XSS攻击。
The course is specifically designed to understand Cross Site Scripting Vulnerability with a complete Practical Hands-On Experience. This course will train the students to setup their own local penetration testing environment to practice in a safe and contained environment. The students will learn what Cross Site Scripting Vulnerability really is, and how different types of XSS works? Then they will follow an Attacking Approach to deeply understand how XSS attacks happen in real life. They will learn to use different vulnerability scanners to find XSS vulnerabilities. They will also learn to prevent and restrict XSS attacks by using methods like - Escaping User Input, Content Security Policy, etc, thus following a Defensive Approach, hence then name of the course: "Cross Site Scripting: Attack & Defense", and last but not the least, they will learn to use different cheat sheets to evade WAFs and Firewalls, and also to prevent XSS attacks by implementing secure coding practices and proper handling of untrusted data.