|
所在平台: Udemy |
课程主页: https://www.udemy.com/course/hacking-android-applications-for-bug-bounty-and-pentesting/
课程评论:没有评论
课程名称:Android应用程序黑客技术:漏洞赏金与渗透测试 课程概述: 欢迎参加我们的课程《Android应用程序黑客技术:漏洞赏金与渗透测试》。本课程旨在帮助您开始Android渗透测试的旅程,掌握正确的工具和方法论。信息安全是一个不断变化的领域,我们将为您提供最新的方法,帮助您建立自己的测试环境,并实践Android渗透测试。 课程内容从基础知识入手,包括Android架构、Android运行时(ART)及Android设备Root的基本概念。接下来将介绍中级概念,如逆向工程Android应用程序和绕过客户端限制(如Root检测和SSL钉扎等)。课程利用多个行业知名与开源应用程序进行测试案例的演示。 您将学习如何识别各种Android应用程序漏洞,包括不安全的数据存储、不安全的日志记录、弱Root检测、不安全的端到端加密,以及REST API中的访问控制问题等。课程旨在教授从逆向APK到理解和识别漏洞、修改应用逻辑并在Android环境中运行修改后的应用程序的一般方法。无论您是初学者还是高级用户,本课程都适合您。我们将通过逐步的实践演示,从基础知识引导您达到高级水平。 课程亮点包括: - Android基础知识 - Windows和Linux下的实验室环境搭建 - 静态与动态分析 - 使用Burpsuite截取流量 - 绕过Root检测 - 绕过SSL钉扎 - 使用objection进行应用程序修补 - Frida代码共享与启动脚本 - 手动逆向和修补应用程序 - Smali语言理解 - 识别客户端加密 - 真实世界漏洞查找案例 期待在课程中与您见面!
Welcome to our course: Android Applications Hacking for Bug Bounty and PentestingThis course is designed to help you kick-start the journey of android pentesting with right tools and methodology. Information security is the ever-changing field, we bring the latest methodology to setup your own environment and get your hands dirty with the android pentesting.This course initiates with basics such as Android Architecture, what is Android Run time (ART), Android device Rooting Basics. Towards the intermediate concepts like Reversing Android Apps, Bypassing client side restrictions such as root detection, SSL Pinning etc. This course leverages multiple industry known & open source applications to demonstrate the test cases.This course will also teaches you how to identify a variety of Android App vulnerabilities such as Insecure Data Storage, Insecure Logging, Weak Root detection, insecure end to end encryption, Access Control issues in REST API etc. Essentially this course is designed to teach the general approach right from reversing the APK, to understand & identify vulnerabilities, modifying the application logic to run the modified application in the android environment. This course is for all levels. We will take you from beginner to advance level. You will learn step-by-step with hands-on demonstrations.The highlights of this course are:Fundamentals of androidLab Setup in Windows & LinuxStatic & Dynamic AnalysisIntercept Traffic using BurpsuiteRoot detection bypassSSL Pinning BypassPatching apps using objectionFrida code share & Startup scriptsReversing & patching applications manuallySmali UnderstandingIdentifying client side encryptionReal world findings WalkthroughSee you inside the course!