Ethical Hacking with JavaScript

所在平台: Udemy

课程主页: https://www.udemy.com/course/ethical-hacking-with-javascript/

课程评论:没有评论

第一个写评论        关注课程

课程简介

课程名称:使用JavaScript进行道德黑客攻击 课程概述: 在这门课程中,您将学习如何利用JavaScript进行道德黑客攻击,专注于发现和利用网页安全漏洞。尤其是,当您发现XSS漏洞后,该如何处理?课程将教您如何展示这些漏洞对客户的潜在危害,以便他们采取必要的修复措施。 课程内容包括: - 对一些常见的网页应用缺陷进行快速回顾。 - 将JavaScript作为攻击工具,展示如何利用这些漏洞及其影响。 - 学习如何篡改网站内容,包括页面、表单和链接的功能。 - 使用HTML表单捕获额外数据并将其发送到您的控制服务器。 - 掌握如何泄露用户cookies并盗取这些信息。 - 学习获取用户凭证、滥用应用身份验证,并实现自定义键盘记录器等技术。 - 处理基于知识的身份验证方案,例如秘密问题/答案的账户重置。 此外,课程还将涵盖更高级的技术,例如连接多个攻击以同时利用几个应用漏洞、创建虚假的论坛帖子、网络钓鱼活动以及使用命令注入访问网络服务器操作系统。最后,我们将介绍一些防御技术,以防止我们发起的各种攻击,确保您能够更有效地保护网页应用。 整门课程均以道德黑客为主题,全部使用JavaScript进行实践学习。

课程评论(0条)

课程详情

You've found a XSS vulnerability....but now what?Has a client ever wanted you to demonstrate the danger of a vulnerability you found for them?If so, then you need to Learn Ethical Hacking with JavaScript! After this course, you will be able to exploit web security vulnerabilities by using a variety of skills and techniques centered on JavaScript.After a quick review of some common web application flaws, we'll jump right into using JavaScript as an offensive weapon against the application and clients.Each topic is presented from the perspective of requiring the pentester to demonstrate how a vulnerability can be exploited and the potential impact of not taking corrective action. The course provides a balanced mix of theory, code, and live demonstrations of each exploit in action.Learn to tamper with site content - altering the page, forms, links, and functionality. Then take it to the next level by abusing HTML forms to capture additional data on form submission, sending that data to a server you control.See how to disclose the contents of user cookies, then quickly move to stealing the cookies and sending them to another server. Learn to steal credentials and abuse application authentication.Further compromise users by capturing mouse interactions and implementing a custom key logger. Learn to abuse knowledge-based authentication schemes such as the secret question/answer approach for account resets.Progress to more advanced techniques where you learn to chain together multiple attacks aimed at exploiting several application vulnerabilities simultaneously. Areas covered here include creating fraudulent forum posts, spear phishing campaigns, and using command injection to access a web server's operating system. And we'll wrap the course up with some defensive techniques you can use to prevent the types of attacks we've been launching at web applications.All Ethical Hacking! All done with JavaScript!

课程标签

0人关注该课程

主题相关的课程