|
所在平台: Udemy |
课程主页: https://www.udemy.com/course/hacking-android-apps-lite-edition/
课程评论:没有评论
**课程名称:** Hacking and Pentesting Android Apps - Lite Edition **课程概述:** 本课程是您迈入移动应用安全领域的入门第一步。专为移动应用安全新手设计,侧重于Android平台。无论您是学生、开发者、QA工程师还是有志于成为道德黑客,本课程都将提供一个动手实践、面向现实世界Android应用程序漏洞的识别和理解的介绍。 我们将使用 publicly available 的、故意设计为有漏洞的Android应用 DIVA (Damn Insecure and Vulnerable App) 作为核心训练环境。通过指导式 walkthroughs(流程演示)和互动练习,您将在一个受控且合乎道德的环境中学习如何发现和利用常见的Android应用程序安全问题。 **您将学到:** * 在识别和分析漏洞方面获得基础知识和实践技能,包括: * 不安全的数据存储(例如,未加密的SharedPreferences和数据库) * 硬编码敏感数据(例如,API密钥、源代码中的密码) * 不安全的日志记录(例如,将秘密泄露到Logcat) * 导出的应用程序组件(例如,其他应用程序可访问的Activities, Services, and Broadcast Receivers) * 输入验证问题(例如,移动应用中的SQL注入) * 不安全的通信(例如,未加密的网络流量) **动手实践训练:** 您将不仅仅是阅读或观看,而是亲手实践: * 使用ADB、JADX、Apktool等工具 * 分析APK文件和反编译Android应用 * 进行静态代码分析 * 探索攻击者如何利用应用程序弱点 **加分项:** 包含互动测验 为了帮助您巩固所学知识,我们包含了一个基于课程练习的测验。这将帮助您: * 评估您对Android漏洞的理解程度 * 为进一步的移动应用安全认证做准备 * 参与团队讨论 **先修要求:** * 对Android应用有基本了解(如何安装、使用APKs) * 熟悉命令行会有帮助,但非必需 * 无需任何安全经验
Welcome to your first step into the world of mobile app security!This entry-level course is designed specifically for those new to mobile application security, with a focus on the Android platform. Whether you're a student, developer, QA engineer, or aspiring ethical hacker, this course offers a hands-on and practical introduction to identifying and understanding real-world vulnerabilities in Android applications.We use DIVA (Damn Insecure and Vulnerable App) - a publicly available, intentionally vulnerable Android app - as our core training environment. Through guided walkthroughs and interactive exercises, you will learn how to discover and exploit common Android app security issues in a controlled and ethical setting.What You'll LearnYou'll gain foundational knowledge and practical skills in identifying and analyzing vulnerabilities such as:Insecure Data Storage (e.g., unencrypted SharedPreferences and databases)Hardcoded Sensitive Data (e.g., API keys, passwords in source code)Insecure Logging (e.g., leaking secrets to Logcat)Exported Application Components (e.g., Activities, Services, and Broadcast Receivers accessible by other apps)Input Validation Issues (e.g., SQL Injection in mobile apps)Insecure Communication (e.g., unencrypted network traffic)Hands-On TrainingYou won't just read or watch - you'll practice:Using tools like ADB, JADX, ApktoolAnalyzing APK files and decompiling Android appsPerforming static code analysisExploring how attackers can exploit app weaknessesBonus: Interactive Quiz IncludedTo help reinforce your learning, we've included a quiz based on the exercises from the course. This will help you:Assess your understanding of Android vulnerabilitiesPrepare for further mobile app security certificationsEngage in team discussionsPrerequisitesBasic knowledge of Android apps (how to install, use APKs)Familiarity with the command line is helpful but not mandatoryNo prior security experience needed!