|
所在平台: Udemy |
课程主页: https://www.udemy.com/course/learning-python-web-penetration-testing/
课程评论:没有评论
课程名称:Python网络渗透测试学习 课程概述:随着网络应用数量的迅速增长,保障这些应用安全的需求也日益增加。网络渗透测试是通过工具和代码对网站或网络应用进行攻击,以评估其对外部威胁的脆弱性。虽然现在有越来越多的复杂工具可用于扫描系统的漏洞,但使用Python可以让测试人员编写特定于系统的脚本,或修改和扩展现有的测试工具,从而发现、利用并记录尽可能多的安全漏洞。本课程将引导您了解网络应用渗透测试的方法论,展示如何使用Python编写适用于每个主要环节的工具。课程将教您如何像安全专业人士和黑客一样,测试网络应用的安全漏洞。 课程内容从介绍网络应用渗透测试过程及专业人士用于执行这些测试的工具开始,随后介绍HTTP及如何使用Python和Requests库与网络应用进行交互。接下来将深入讨论网络应用渗透测试的方法论,并用Python示例支持每个部分的理解。最后,课程会测试这些工具在专为本课程创建的易受攻击网络应用上的效果。不要只依赖自动化工具,学习编写自己的工具并修改现有工具以满足您的需求!本课程将为您作为安全专业人士的职业生涯提供一个良好的起点,帮助您获得编写定制工具和修改现有Python工具以适应不同场景的必要技能。 关于讲师:Christian Martorella在信息安全领域工作已有16年,目前担任微软Skype产品安全团队的首席项目经理,专注于软件安全和DevOps环境中的安全自动化。之前,他在Verizon Business担任威胁和漏洞实践领导,领导顾问团队在EMEA地区为金融服务、电信、公用事业和政府等各个行业提供安全测试服务。Christian在IT安全的各个领域都有广泛的经验,拥有独特的技能和网络安全视角。他是Edge-Security团队的联合创始人并活跃于此,发布安全工具和研究,参与了多个开源安全测试和信息收集工具的开发,如OWASP WebSlayer、Wfuzz和theHarvester等,均包括在渗透测试Linux发行版Kali中。Christian在多个安全会议上发表过演讲,并组织过20多场FIST会议,为安全测试领域的专业人士和爱好者提供了交流平台。Christian持有华威商学院的工商管理硕士学位以及多个安全认证,如CISSP、CISM、CISA等。
With the huge growth in the number of web applications in the recent times, there has also been an upsurge in the need to make these applications secure. Web penetration testing is the use of tools and code to attack a website or web app in order to assess its vulnerabilities to external threats. While there are an increasing number of sophisticated ready-made tools to scan systems for vulnerabilities, the use of Python allows testers to write system-specific scripts, or alter and extend existing testing tools to find, exploit, and record as many security weaknesses as possible. This course will walk you through the web application penetration testing methodology, showing you how to write your own tools with Python for every main activity in the process. It will show you how to test for security vulnerabilities in web applications just like security professionals and hackers do. The course starts off by providing an overview of the web application penetration testing process and the tools used by professionals to perform these tests. Then we provide an introduction to HTTP and how to interact with web applications using Python and the Requests library. Then will follow the web application penetration testing methodology and cover each section with a supporting Python example. To finish off, we test these tools against a vulnerable web application created specifically for this course. Stop just running automated tools-write your own and modify existing ones to cover your needs! This course will give you a flying start as a security professional by giving you the necessary skills to write custom tools for different scenarios and modify existing Python tools to suit your application's needs.About The AuthorChristian Martorella has been working in the field of Information Security for the last 16 years, and is currently working as Principal Program Manager in the Skype Product Security team at Microsoft. Christian's current focus is on software security and security automation in a Devops world. Before this, he was the Practice Lead of Threat and Vulnerability for Verizon Business, where he led a team of consultants in delivering security testing services in EMEA for a wide range of industries including Financial Services, Telecommunications, Utilities, and Government. Christian has been exposed to a wide array of technologies and industries, which has given him the opportunity to work in every possible area of IT security and from both sides of the fence, providing him with a unique set of skills and vision on Cyber Security. He is the co-founder and an active member of Edge-Security team, who releases security tools and research. Christian has contributed to open source security testing and information gathering tools such as OWASP WebSlayer, Wfuzz, theHarvester, and Metagoofil, all included in Kali, the penetration testing Linux distribution. Christian presented at Blackhat Arsenal USA, Hack.Lu, What The Hack!, NoConName, FIST Conferences, OWASP Summits, OWASP meetings (Spain, London, Portugal, and Venice), and Open Source Intelligence Conference (OSIRA). In the past, Christian has organized more than 20 FIST Conferences in Barcelona, providing a forum for professionals and amateurs interested in Security Testing. Christian holds a Master's degree in Business Administration from Warwick Business School, and multiple security certifications such as CISSP, CISM, CISA, OPSA, and OPST.