|
所在平台: Udemy |
课程主页: https://www.udemy.com/course/hands-on-penetration-testing-labs-30/
课程评论:没有评论
课程名称:动手渗透测试实验室 3.0 课程概述:欢迎参加“动手渗透测试实验室 3.0”课程!这是一门独立的课程,可以与第一和第二部分单独学习或按顺序学习。本课程将专注于实践操作,最小化理论部分,目标是帮助学生为实际的渗透测试工作以及相关的实践认证(如OSCP)做好准备。学生需要具备可靠的互联网连接和能够支持至少两个虚拟机的电脑,建议拥有至少8 GB的RAM(最好是16 GB或32 GB),以便构建更高级的虚拟实验室进行渗透测试技能的练习。 本课程将使用Virtual Box作为虚拟化软件,安装行业标准的渗透测试操作系统Kali Linux,并设置多个故意存在漏洞的虚拟机器,演示网络服务和网页应用中的漏洞。我们将走过各种战术、技巧和流程,以模拟攻击者的活动。课程内容包括枚举、漏洞扫描,以及自动化和手动利用,具体涵盖端口扫描、服务枚举、本地文件包含、网页目录暴力破解、缓冲区溢出利用开发、SQL注入、跨站脚本攻击、各种类型的反向shell、本地特权提升等重要渗透测试技能。 课程中使用的技术截至2019年6月,随着技术的不断变化,您在学习时可能会遇到与视频中略有不同的软件,但通常可以通过快速搜索或我的帮助来解决问题。鼓励学生独立进行故障排查,因为研究和解决问题的能力是渗透测试人员及IT专业人员至关重要的技能之一。 期待与大家的交流,希望您享受这门课程,并欢迎您留下评论,以帮助我吸引更多的学生和现有或志向中的网络安全专业人士。
NOTE: This is independent from Hands-on Penetration Testing Labs 1.0 and 2.0. All three are standalone courses and can be taken in any order, or on their own.Hello students, and welcome to my Hands-on Penetration Testing Labs 3.0 course. If you're familiar with my previous courses, this is part three of the series. We're going to be diving straight into hands-on technical labs with little focus on theory, as in my opinion this is the best way to prepare for the actual job and for hands-on practical certifications such as OSCP. There's no better way as a penetration tester to gain the raw skills that are needed on the job than to actually use and master the necessary technology and skills.I should mention right now that this course requires a reliable Internet connection, and a decent laptop or PC which can support at least two virtual machines. I suggest that you have at least 8 GB of RAM, but the more the better, especially if you want to make an advanced virtual lab in which to practice and hone your pentesting skills. Ideally, you should have 16 GB or 32 GB of RAM and a decent processor, but you can get away with less.During our course work we'll be using Virtual Box as a software hypervisor in order to spin up Kali Linux, which is an industry standard penetration testing operating system. We'll also be setting up several intentionally vulnerable VMs to demonstrate vulnerabilities within a variety of network services and web applications, walking through various tactics, techniques, and procedures to simulate adversarial activity. I'll be providing all of the necessary software, which is completely free and open source.We'll be covering enumeration, vulnerability scanning, and automated and manual exploitation. More specifically, we'll be going over key essential pentesting skills such as port scanning and service enumeration, local file inclusion, web directory brute forcing, buffer overflows exploit development, SQL injection, Cross-Site Scripting, various types of reverse shells, a variety of local privilege escalation, and much more.All of the technology which is utilized within these recordings is current as of June 2019. Technology is constantly changing, so some of the software seen in these videos may be different when you take the course. However, it should be similar enough for you to figure out with quick Google searches, or with my assistance if needed. You can always reach out to me via the messaging or Q & A system, although I highly encourage you to perform troubleshooting on your own, as the ability to research and troubleshoot is one of the single most important skill sets as a penetration tester and IT professional in general.I'm looking forward to working with all of you, and hope you enjoy my course. Please leave a review if you enjoy my course, as it allows me to reach more and more dedicated students and existing or aspiring cyber security professionals.