|
所在平台: Udemy |
课程主页: https://www.udemy.com/course/master-the-xsscross-site-scripting-for-real-world-apps/
课程评论:没有评论
课程名称:掌握 XSS(跨站脚本攻击)在真实世界应用中的应用 课程概述:跨站脚本攻击(XSS)是一个广为人知的重要漏洞,尤其在漏洞赏金项目中具有重要性。XSS 能够劫持用户的 Cookie 和会话,从而可能导致账户被接管。然而,随着漏洞赏金领域的竞争加剧以及应用程序安全性的增强,发现 XSS 问题变得更加困难,因此我们必须更加依赖手动测试方法而不是自动化工具。在本课程中,讲师提供了大量新鲜的内容,其中许多将是您从未见过的有趣内容。除了账户接管,课程还涵盖了其他与 XSS 相关的攻击,例如键盘记录攻击、内容操控攻击和开放重定向攻击。此外,课程中还展示了如何将 XSS 与其他漏洞(如文件上传、IDOR 等)进行链式攻击。通过这门课程,您将能够学习如何在真实世界应用中发现跨站脚本攻击,构建适用于不同类型攻击的有效载荷,理解通过 XSS 进行账户接管所需的 Cookie、会话和本地存储的知识,以及理解链式攻击的不同条件。同时,您还将学习如何利用开放重定向、键盘记录和内容操控等其他漏洞,并学习如何绕过安全应用程序的不同限制。所有内容均通过真实目标和不同实验室资源进行演示。需要注意的是,课程所展示的所有内容仅用于教育目的,请勿以恶意或不当方式使用,以伤害任何其他组织。
Cross-site scripting is one of the known and important vulnerabilities in Bug bounty, cross scripting has ability to hijack user cookies and sessions and can possibly perform account takeover but nowadays due to increasing competition in bug bounty and more security in applications it is hard to find XSS issues we now have to rely on manual things rather than automation tools, scripts to find a better issue, in this course, I have covered a lot of fresh content and things which will be definitely new and interesting for you.other than account takeovers I have covered other interesting attacks with xss like keylogger attacks, content manipulation attacks, and open redirection.Additionally, i have covered the session where i am showing how you can chain xss with other vulnerabilities like file upload, IDOR etc.From this course, you will be able to learn Finding cross-site scripting in the real-world applicationLearning how to build your own payloads for different types of attacks possible with cross-site scriptingunderstanding account takeovers via xss with understanding cookies, session, local storage and understanding conditions required for account takeoverLearning how to chain different vulnerabilities with xss with other vulnerabilities like file upload, IDOR(Indirect object reference), subdomain takeover, CVEsLearning how to exploit using other vulnerabilities like open redirection, keylogger and content manipulation attackLearning to bypass different restrictions of secure applicationall the things are demonstrated via real targets and different labs resourcesDisclaimer: All the things demonstrated in the course is for educational purpose only don't use this malicious or bad way to harm any other organisation