Learn Bug Bounty Hunting & Web Security Testing From Scratch

所在平台: Udemy

课程主页: https://www.udemy.com/course/learn-bug-bounty-hunting-web-security-testing-from-scratch/

课程评论:没有评论

第一个写评论        关注课程

课程简介

课程名称:从零开始学习漏洞赏金狩猎与网络安全测试 课程概述:欢迎参加我的全面课程《漏洞赏金狩猎与网络安全测试》。该课程不要求任何先前知识,从基础开始,逐步引导你达到高级水平,使你能够发现任何 Web 应用程序中的大量漏洞(包括 OWASP 前十名漏洞),无论使用哪些技术或运行于何种云服务器。课程注重实用性,同时不忽视理论,首先教你网站的工作原理、所用技术及其协同工作方式,并开始黑客攻击与漏洞狩猎。通过实例,你将学习如何发现安全漏洞,而非乏味的讲座。 课程分为多个部分,每个部分旨在教授 OWASP 前十名安全威胁中常见的安全漏洞。每节课通过多个实践示例,逐步讲解安全漏洞的成因及发现方法,从简单到复杂。此外,你还将学习绕过过滤器和安全措施的高级技巧。课程中将介绍各种黑客和安全概念、工具和技术,所有内容均以实例和实践为主,避免无意义的讲座。 课程结束时,我将为你展示一个为期两小时的渗透测试或漏洞狩猎过程,帮助你将所学知识结合应用于真实网站以发现漏洞。我将展示如何分析目标、拆解target以发现大多数人认为是安全的功能中的漏洞。 课程还将覆盖以下主要安全漏洞和脆弱性: - 信息泄露 - IDOR(不安全的直接对象引用) - 访问控制缺失 - 目录/路径遍历 - Cookie 操作 - CSRF(客户端请求伪造) - OAUTH 2.0 - 注入漏洞(命令注入、盲注等) - HTML 注入 - XSS(跨站脚本攻击) - 绕过安全过滤器(CSP 等) - SQL 注入及盲注 - SSRF(服务器请求伪造)等 课程主题包括信息收集、端点发现、HTTP 头、状态码、方法、输入参数、Cookies、HTML 和 JavaScript 基础知识、代码分析等。你将使用以下工具达成上述目标:Ferox Buster、WSL、开发工具、Burp Suite(基础、代理、侵入者等)。 通过本课程,你将获得 24/7 的支持,任何问题均可在问答部分提问,我们将在 15 小时内回复你。欢迎查看课程大纲和预告片以获取更多信息!

课程评论(0条)

课程详情

Welcome to my comprehensive course on Bug Bounty Hunting & Web Security Testing course. This course assumes you have NO prior knowledge, it starts with you from scratch and takes you step-by-step to an advanced level, able to discover a large number of bugs or vulnerabilities (including the OWASP top 10) in any web application regardless of the technologies used in it or the cloud servers that it runs on.This course is highly practical but doesn't neglect the theory, we'll start with basics to teach you how websites work, the technologies used and how these technologies work together to produce these nice and functional platforms that we use everyday. Then we'll start hacking and bug hunting straight away. You'll learn everything by example, by discovering security bugs and vulnerabilities, no boring dry lectures.The course is divided into a number of sections, each aims to teach you a common security bug or vulnerability from the OWASP top 10 most common security threats. Each section takes you through a number of hands-on examples to teach you the cause of the security bug or vulnerability and how to discover it in a number of scenarios, from simple to advanced. You'll also learn advanced techniques to bypass filters and security measures. As we do this I will also introduce you to different hacking and security concepts, tools and techniques. Everything will be taught through examples and hands-on practicals, there will be no useless or boring lectures!At the end of the course I will take you through a two hour pentest or bug hunt to show you how to combine the knowledge that you acquired and employ it in a real-life scenario to discover bugs and vulnerabilities in a real website! I will show you how I approach a target, analyse it, and take it apart to discover bugs and vulnerabilities in features that most would think are secure!As mentioned you'll learn much more than just how to discover security bugs in this course, but here's a list of the main security bugs and vulnerabilities that will be covered in the course:Information Disclosure.IDOR (Insecure Direct Object Reference).Broken Access Control.Directory / Path Traversal.Cookie Manipulation.CSRF (Client-Side Request Forgery).OAUTH 2.0.Injection Vulnerabilities.Command Injection.Blind Command Injection.HTML Injection.XSS (Cross-Site Scripting).Reflected, Stored & DOM Based XSS.Bypassing Security Filters.Bypassing CSP (Content Security Policy).SQL Injection.Blind SQLi.Time-based Blind SQLi.SSRRF (Server-Side Request Forgery).Blind SSRF.XXE (XML External Entity) Injection.Topics:Information gathering.End point discovery.HTTP Headers.HTTP status codes.HTTP methods.Input parameters.Cookies.HTML basics for bug hunting.Javascript basics for bug hunting.XML basics for bug hunting.Filtering methods.Bypassing blacklists & whitelists.Bug hunting and research.Hidden paths discovery.Code analyses.You'll use the following tools to achieve the above:Ferox Buster.WSL.Dev tools.Burp Suite:Basics.Burp Proxy.Intruder (Simple & Cluster-bomb).Repeater.Collaborator.With this course you'll get 24/7 support, so if you have any questions you can post them in the Q & A section and we'll respond to you within 15 hours.Checkout the curriculum and the course teaser for more info!

课程标签

0人关注该课程

主题相关的课程