A fast guide to Master Burp Suite for Bug Bounty & PenTests!

所在平台: Udemy

课程主页: https://www.udemy.com/course/learn-burpsuite-fast/

课程评论:没有评论

第一个写评论        关注课程

课程简介

课程名称:快速指南:掌握Burp Suite进行漏洞赏金与渗透测试! 课程概述:本课程将教授您关于Burp Suite的所有必要知识,以便开始进行漏洞赏金猎杀或成为专业的渗透测试人员。课程由一位在信息安全领域拥有多年经验的专业人士授课,他拥有多项认证,并与众多客户在多个地区合作。最重要的是,他几乎每天都在客户项目中使用Burp Suite,对如何利用这一工具以获得实际成果有深入了解。 本课程详细讲解了Burp Suite的所有功能,包括第三方扩展,以确保测试的各个方面都得到覆盖。您将学习如何使用Burp Suite查找OWASP十大漏洞,这对任何专业测试来说至关重要。除了教您如何专业地使用Burp Suite,课程还将分享一些专业测试员使用的特定技巧,以充分利用其功能,涵盖所有类型的测试,例如API和移动应用测试。 作为额外奖励,您将看到使用Burp Suite查找OWASP十大问题的示例,包括: - A01 破碎的访问控制 - A02 加密失败 - A03 注入 - A04 不安全设计 - A05 安全配置错误 - A06 易受攻击和过时的组件 - A07 身份识别和认证失败 - A08 软件和数据完整性失败 - A09 安全日志和监控失败 - A10 服务器端请求伪造(SSRF) 您不会在普通的Burp Suite课程中找到如此详细的内容。让我们一起行动,赚取漏洞赏金吧!

课程评论(0条)

课程详情

This course will teach everything you need to know about Burp Suite to start Bug Bounty hunting or to become a professional penetration tester. The course is taught by an InfoSec professional who has been in the industry for multiple years, has multiple certifications and has worked with hundreds of clients in many regions. Most importantly, he has used Burp Suite almost daily as part of the hundreds of client engagements and knows how to use the tool to achieve results.This course goes into detail on all areas of Burp Suite, including 3rd party extensions to ensure all areas of testing are covered. You will learn how to use Burp Suite to find everything in the OWASP TOP 10 which is vital to any professional test.Not only will this course teach you how to use Burp Suite as a professional, but you will also learn the specific tips and tricks that a professional tester uses to go beyond the program to really utilise it's features for all types of testing. For example, API and Mobile application testing. As an added bonus, you will be shown some examples of finding OWASP TOP 10 Issues using Burp Suite:A01 Broken Access ControlA02 Cryptographic FailuresA03 InjectionA04 Insecure DesignA05 Security MisconfigurationA06 Vulnerable and Outdated ComponentsA07 Identification and Authentication FailuresA08 Software and Data Integrity FailuresA09 Security Logging and Monitoring FailuresA10 Server Side Request Forgery (SSRF)You will not find this level of detail in an average Burp Suite course. Let's do this, lets make that bug bounty money!

课程标签

0人关注该课程

主题相关的课程