Kali Linux Web App Pentesting Labs

所在平台: Udemy

课程主页: https://www.udemy.com/course/kali-linux-web-app-pentesting-labs/

课程评论:没有评论

第一个写评论        关注课程

课程简介

课程名称:Kali Linux Web App Pentesting Labs 课程概述:欢迎参加Kali Linux Web App Pentesting Labs课程!本课程将完全采用实践教学,重点关注易受攻击的网络应用程序的利用。我们将搭建一个实验环境,包括Kali Linux和若干个故意设计为脆弱的网络应用程序,如Beebox、SQL注入实验室、OWASP Juice Shop和WebGoat。在课程期间,我们将专注于最常见的网络应用程序漏洞及其利用方法。我们的学习框架将基于录制时最新的OWASP 2017前十名,用于改善网络应用程序安全的组织,学习这些是每位渗透测试者的基本要求。课程将深入探讨OWASP 1-9,因为第十项不专门针对渗透测试,而是侧重于防御部分。此外,我们将详细覆盖每一个关键主题,包括手动和自动的漏洞检测和利用方法。学员将获得行业标准工具的实践经验,如Burpsuite、Nmap、Nikto、Sqlmap等。通过多年的网络安全学术观察,大多数课程仅教授理论,学员通过写作和选择题证明自己的能力,然而这并不能为现实世界做准备,尤其是渗透测试领域,技术技能至关重要。本课程旨在弥合这一差距。课程开头将包括下载、安装和配置进行全面的网络应用渗透测试所需的各个组件。请准备好跟随实验立刻开始。期待与大家的合作!如在实验中有任何问题,请随时通过消息系统或问答部分与我联系。

课程评论(0条)

课程详情

Welcome to my Kali Linux Web App Pentesting Labs course! This course will be 100% hands-on, focusing specifically on exploitation of vulnerable web applications. We'll be building a lab environment consisting of Kali Linux, and several intentionally vulnerable web applications including Beebox, SQL injection labs, OWASP Juice Shop, and WebGoat. Through the duration of this course, we'll be focusing upon the most prevalent web application vulnerabilities and how to exploit them. As a framework for our learning approach, we'll be using the most recent version of OWASP at the time of this recording, which is OWASP 2017 top 10. OWASP is an organization which focuses upon improving the security of web applications and is a fundamental and necessary component to learn for aspiring pentesters. We'll be covering OWASP 1-9, because 10 does not apply specifically to pentesting, and is focused on the defensive side. Additionally, we'll be covering each of these in great detail over this course. The primary topics within this course are both manual and automated methods of detection and exploitation of web application web application vulnerabilities. You'll be getting hands-on exposure to industry standard tools such as Burpsuite, Nmap, Nikto, Sqlmap, and many more. From what I've seen over the years in cybersecurity academia, including certifications, hands-on skills are highly lacking, save for the offensive security certs. This is because the majority of courses I've seen only teach theory, and have students prove their competency through writing and answering multiple choice questions. This does not prepare one for the real world, especially for pentesting where technical skills are paramount. This course aims to bridge that gap. The beginning of this course will consist of downloading, installing, and configuring the components necessary for comprehensive hands-on web application penetration testing in a lab environment. Please get ready to hit the ground running and follow along with these labs, as we'll be getting started right away in the subsequent lecture. I really look forward to working with all of you. If you have any questions during any of the labs, please feel free to reach out to me directly with the messaging system or Q & A section.

课程标签

0人关注该课程

主题相关的课程