|
所在平台: Udemy |
课程主页: https://www.udemy.com/course/introduction-of-web-security/
课程评论:没有评论
课程名称:网络安全入门 课程概述:本课程旨在为零基础的学员提供网络安全的基本知识,深入了解网络安全的攻击与防御。学生将学习现代网络安全漏洞的分类,以及如何识别网络应用中的安全缺陷。课程内容包括:1) 新网络概念/术语的介绍 2) 漏洞示例和基础编程 3) 实验练习以巩固学习。 课程大纲: 1. HTTP基础 2. 用户交互攻击 3. 客户端数据泄露攻击 4. 安全绕过 [仍在上传中...] 5. Python语言基础 [仍在上传中...] 6. 服务器和后端设置介绍 [仍在上传中...] 7. 服务器端信息泄露 [仍在上传中...] 8. 攻击文件上传功能 [仍在上传中...] 9. 命令注入与网络应用防火墙(WAF)绕过 [仍在上传中...] 本课程强调实践学习,认为仅靠理论和概念的学习无法让学生充分理解安全缺陷。因此,课程中设计了多个实验练习,帮助学生深入理解所学的安全概念。课程将从HTTP(超文本传输协议)的基础知识开始,逐步深入到客户端安全漏洞的探讨。在进入服务器端漏洞内容之前,将介绍一些基础的Python编程知识,以帮助学生阅读代码并进行低级别代码审查,从而识别漏洞的根本原因。掌握这些知识后,学生还可以参与漏洞奖励计划或漏洞披露计划,为自己积累作品集并在安全领域立足。
In this course, you will learn everything about the basic of offensive web security from scratch with zero IT knowledge. Students enrolled in the program will learn modern web security vulnerability classes and how to identify security flaws in web applications. The methodology for the course includes:1) Introduction of new web concept/terminology2) Vulnerability illustrations and basic programming3) Lab exercises to reinforce learningCourse outline---------1. HTTP basics2. User interaction attack3. Client data disclosure attack4. Security bypasses [Still uploading...]5. Basic of Python language [Still uploading...]6. Introduction of Server and backend setup [Still uploading...]7. Server-side information disclosure [Still uploading...]8. Attack file upload function [Still uploading...]9. Command injection and Web Application Firewall (WAF) bypass [Still uploading...]The only way to learn is through hands-on experience. I believe learning through just theory and concepts will not allow students to fully understand the security flaws that were introduced. Therefore, in this course, I have prepared a number of lab exercises that allow students to fully understand the security concept that was introduced to them.The course will begin covering the basic concept of HTTP (Hypertext Transfer Protocol) and move on to covering client-side security vulnerabilities. After which, before diving into the server-side vulnerability, the course would introduce some basic Python programming language to give students the advantage to read code and be able to conduct a low-level code review to identify the root cause of the vulnerability.Honed with this knowledge, the student can also participate in Bug bounty or Vulnerability Disclosure programs to begin building up their portfolios and create a foothold in the security field.