|
所在平台: Udemy |
课程主页: https://www.udemy.com/course/learn-website-hacking-penetration-testing-from-scratch/
课程评论:没有评论
课程名称:网站黑客攻击/渗透测试 课程概述: 本课程为您提供了一次全面的学习网站黑客攻击和渗透测试的机会。尽管我的其他课程中涵盖了网站黑客的基本知识,但本课程将深入探讨更多的技术和漏洞,包括高级利用、高级后期利用、绕过安全措施等内容。本课程假定您没有任何黑客知识,从零基础开始,逐步提升至高级水平,能够像黑帽黑客一样攻击网站,并像安全专家一样保护它们。 课程内容: 1. **信息收集**:学习如何全面收集目标网站的信息,包括DNS信息、使用的服务、子域名、未发布的目录、敏感文件及用户电子邮件等,这些信息对成功攻击目标网站至关重要。 2. **发现、利用与缓解**:通过多个实践示例,学习OWASP十大常见安全威胁中的常见漏洞,从发现漏洞到利用漏洞,并学习如何缓解这些问题。主要涵盖的信息泄露、文件上传、代码执行、SQL注入等常见漏洞。 3. **后期利用**:学习如何利用已获得的访问权限,包括如何执行系统命令、访问其他网站、上传/下载文件、访问数据库等高级技术。 本课程重实践,结合案例和动手实践,避免无聊的理论讲解。课程中将介绍包括Kali Linux、Burp Suite、Metasploit等在内的多种工具,同时提供24/7支持,以便答疑解惑。 重要提示:本课程仅用于教育目的,所有攻击均在我自己的实验室内或针对经过授权的系统进行。本课程由Zaid Sabih和zSecurity团队独立创建,完成后将获得Udemy的课程完成证书,其他机构未参与其中。
Last Update: May 2024Notes: Although website hacking is covered in one of my other courses, that course only covers the basics where this course dives much deeper in this topic covering more techniques, more vulnerabilities, advanced exploitation, advanced post exploitation, bypassing security and more!This course focuses on website hacking, I have a different course that teaches bug hunting from scratch.Welcome to my comprehensive course on Website hacking / penetration testing. This course assumes you have NO prior knowledge in hacking, it starts with you from scratch and takes you step-by-step to an advanced level, being able to hack websites like black-hat hackers and secure them like security experts! This course is highly practical but doesn't neglect the theory, we'll start with basics to teach you how websites work and install the needed software (on Windows, Linux and Apple Mac OS). Then we'll start hacking straight away. You'll learn everything by example, by discovering vulnerabilities and exploiting them to hack websites. No boring dry lecturesBefore jumping into hacking, you'll first learn how to gather comprehensive information about the target website. Then the course is divided into a number of sections, each aims to teach you a common vulnerability from the OWASP top 10 most common security threats. Each section takes you through a number of hands-on examples to teach you the cause of the security bug or vulnerability and how to discover it and exploit it in a number of scenarios, from simple to advanced, ultimately allowing you to hack the target website. You'll also learn advanced techniques to bypass filters and security, escalate your privileges, access the database and much more post-exploitation techniques. As we do this I will also introduce you to different hacking and security concepts, tools and techniques. Everything will be taught through examples and hands-on practicals, there will be no useless or boring lectures!Here's a more detailed breakdown of the course content:1. Information Gathering - In this section you'll learn how to gather comprehensive information about a target website, you'll learn how to discover its DNS information, the services used, subdomains, un-published directories, sensitive files, user emails, websites on the same server and even the hosting provider. This information is crucial as it expands the attack surface, increasing our changes of successfully hacking the target website.2. Discovery, Exploitation & Mitigation - In this section you will learn how to discover, exploit and mitigate a common vulnerabilities from the OWASP top 10 most common security threats. This section is divided into a number of subsections. Each subsection takes you through a number of hands-on examples to teach you the cause of the vulnerability, how to discover it and how to exploit it in a number of scenarios, from simple to advanced, ultimately allowing you to hack the target website. You'll also learn advanced techniques to bypass filters and security. Finally we will analyse the code causing these vulnerabilities and d,Here's a list of the main vulnerabilities that will be covered in this section.Information Disclosure.File upload.Code Execution.Local File Inclusion.Remote File Inclusion.SQL Injection.Cross Site Scripting (XSS).Insecure Session Management.Brute Force & Dictionary Attacks.CSRF (Client-Side Request Forgery).3. Post Exploitation - In this section you will learn what can you do with the access you gained by exploiting the above vulnerabilities. You will learn how to convert reverse shell access to a Weevely access and vice versa, how to execute system commands on the target server, navigate between directories, access other websites on the same server, upload/download files, access the database and even download the whole database to your local machine. You will also learn how to bypass security, privilege escalation and do all of the above with limited permissions on the server! You'll use the following tools to achieve the above:Kali Linux.Weevely.THC-Hydra.Netcat.Dev tools.Burp Suite.OWASP Zap.Metasploit.BeEF.Dirb.Maltego.Knockpy.With this course you get 24/7 support, so if you have any questions you can post them in the Q & A section and we'll respond to you within 15 hours.Checkout the curriculum and the course teaser for more info!Notes: This course is created for educational purposes only and all the attacks are launched in my own lab or against systems that I have permission to test.This course is totally a product of Zaid Sabih & zSecurity, no other organization is associated with it or a certification exam. Although, you will receive a Course Completion Certification from Udemy, apart from that NO OTHER ORGANIZATION IS INVOLVED.