Mastering Directory Traversal - The Ultimate Hands-On Course

所在平台: Udemy

课程主页: https://www.udemy.com/course/mastering-directory-traversal-the-ultimate-hands-on-course/

课程评论:没有评论

第一个写评论        关注课程

课程简介

课程名称:掌握目录遍历 - 终极实战课程 课程概述:目录遍历(也称为文件路径遍历)是一种漏洞,允许攻击者读取运行应用程序的服务器上的任意文件。这些文件可能包含凭据、系统配置和应用代码。在某些情况下,攻击者不仅可以读取任意文件,还有可能写入任意文件,通常会导致系统完全被攻陷。因此,掌握识别和利用目录遍历漏洞的能力已经成为一项基本技能。 本课程深入探讨目录遍历漏洞的技术细节,从黑箱和白箱的角度学习如何发现这些类型的漏洞,以及利用这些漏洞的不同方法。我们还将讨论防止和缓解目录遍历漏洞的技术。 本课程并非普通的基础课程,而是理论与实践的完美结合!课程包含6个不同难度级别的实操实验,教授如何手动利用漏洞以及如何在Python中脚本化/自动化你的攻击。如果你是渗透测试人员、应用安全专家、漏洞赏金猎人、软件开发者、道德黑客或对Web应用安全感兴趣的任何人,这门课程都非常适合你!

课程评论(0条)

课程详情

Directory Traversal (or also known as file path traversal) is a vulnerability that allows an attacker to read arbitrary files on the server that is running the application. This includes files that contain credentials, system configuration and application code. In some cases, not only could you read arbitrary files, but you could also write to arbitrary files which usually leads to a full system compromise. Therefore, mastering the ability to identify and exploit directory traversal vulnerabilities has become an essential and foundational skill.In this course, we dive into the technical details behind directory traversal vulnerabilities, how to find these types of vulnerabilities from a black-box and white-box perspective and the different ways to exploit these types of vulnerabilities. We also cover prevention and mitigation techniques that you can use to prevent directory traversal vulnerabilities.This is not your average course that just teaches you the basics. It's the perfect mix of theory and practice! The course contains 6 hands-on labs of varying difficulty levels that teach you how to first manually exploit the vulnerability and then how to script/automate your exploit in Python. If you're a penetration tester, application security specialist, bug bounty hunter, software developer, ethical hacker, or just anyone interested in web application security, this course is for you!

课程标签

0人关注该课程

主题相关的课程