Cross Site Scripting (XSS) Attacks for Pentesters

所在平台: Udemy

课程主页: https://www.udemy.com/course/cross-site-scripting-xss-attacks-for-pentesters/

课程评论:没有评论

第一个写评论        关注课程

课程简介

课程名称:渗透测试者的跨站脚本(XSS)攻击 课程概述: 跨站脚本(XSS)仍然是现代和传统Web应用程序中最常见的注入漏洞之一。本课程将深入讲解XSS,并讨论较少被提及的XSS衍生物,诸如变异XSS(mXSS)和相对路径覆盖XSS(RPO XSS)。如果您对不同类型的XSS、XSS中的不同上下文以及真实世界的红队XSS利用感兴趣,那么本课程非常适合您。只需花费2小时,便可以深入掌握XSS。课程完全注重实践,每个概念都有演示或练习的解释,这使学生可以尝试他们所学的内容。 本课程将解释XSS的定义、类型及其上下文,并讨论在真实世界中如何利用XSS漏洞进行攻击,包括键盘记录、Cookie窃取、网络钓鱼、受害者/浏览器/网络指纹识别以及更高级的攻击,如反向TCP Shell、Driveby攻击等,所有这些均可通过OWASP Xenotix XSS Exploit Framework实现。OWASP Xenotix XSS Exploit Framework是由本课程作者开发的先进的跨站脚本漏洞检测和利用框架。 最后,我们还将讨论XSS的保护措施,包括输入验证、上下文敏感输出转义和各种安全头,帮助我们减轻XSS风险。作为福利,您将获得“终极XSS保护备忘单”,该备忘单由OpenSecurity提供。 课程内容覆盖以下主题: - 什么是XSS? - 为什么要学习XSS? - XSS的类型: - 反射型XSS或非持久型XSS - 存储型XSS或持久型XSS - DOM XSS - 变异XSS(mXSS) - 相对路径覆盖XSS(RPO XSS) - XSS的来源 - XSS中的不同上下文: - HTML上下文 - 属性上下文 - URL上下文 - 样式上下文 - 脚本上下文 - 真实世界中的攻击 - 如何使用OWASP Xenotix XSS Exploit Framework进行XSS利用 - XSS的保护措施 总之,本课程旨在通过实践和理论相结合的方式,帮助学员全面了解和掌握XSS攻击及其防护技术。

课程评论(0条)

课程详情

Cross Site Scripting or XSS is still one of the most common injection vulnerability that exist in modern as well as legacy Web Applications. This course will teach XSS in-depth and even talk about the lesser known derivatives of XSS called Mutation XSS (mXSS) and Relative Path Overwrite XSS (RPO XSS). If you are interested in learning about the different types of XSS, different context in XSS, and about real world red team XSS Exploitation, then this course is for you and it does not take hours. Invest just 2 hours and master XSS in-depth. This course is completely hands-on and every concept is explained with a demo or exercise. This allow students to try out all the things that they have learned. This course explains XSS, its types, context and also discuss about exploiting XSS vulnerabilities in real world where you can perform offensive attacks ranging from Keylogging, Cookie Stealing, Phishing, Victim/Browser/Network Fingerprinting to much advanced attacks like reverse TCP shell, Driveby Attacks etc with OWASP Xenotix XSS Exploit Framework. OWASP Xenotix XSS Exploit Framework is an Advanced Cross Site Scripting Vulnerability Detection and Exploitation Framework written by the author of this course. Finally we will also discuss about XSS Protection where we discuss about Input Validation, Context Sensitive output escaping and the various security headers that help us to mitigate XSS. Also as a take away you will get "The Ultimate XSS Protection Cheat sheet" from OpenSecurity. The course will cover the following things. What is XSS? Why XSS? Types of XSS Reflected XSS or Non-Persistent XSS Stored XSS or Persistent XSS DOM XSS mXSS or Mutation XSS RPO or Relative Path Overwrite XSS What are the Source of XSS? Different Contexts in XSS HTML Context Attribute Context URL Context Style Context Script Context Attacks in Real World Exploiting XSS with OWASP Xenotix XSS Exploit Framework XSS Protection

课程标签

0人关注该课程

主题相关的课程